Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Data Breach by Over 300 Chrome Extensions Uncovered

Data Breach by Over 300 Chrome Extensions Uncovered

Posted on February 14, 2026 By CWS

More than 300 Chrome extensions have been identified as threats to user privacy, leaking or stealing sensitive browser data. Security researchers have sounded the alarm over these malicious extensions that have been installed by millions of users worldwide, compromising their data security.

Unmasking the Threat

In a comprehensive study analyzing network traffic from Chrome extensions, researchers uncovered 287 applications that transmit user browsing history and search engine results. The findings reveal that some extensions inadvertently expose data to unsecured networks, while others deliberately send information to data collection servers, either for profit or with harmful intentions.

The scale of this issue is significant, with over 37.4 million users affected. Of these, approximately 27.2 million have installed 153 extensions confirmed to leak browsing history upon installation. The investigation led by researcher Q Continuum also flagged over 200 additional extensions that share author details with the offending apps, raising suspicion about their integrity.

Connections and Implications

Q Continuum’s research suggests that these malicious activities might be orchestrated by data brokers, rather than the extension developers themselves. The extensions have been linked to 32 different entities, with ties to known spyware distributors, indicating a potentially coordinated effort to monetize stolen user data.

In parallel, a report by LayerX has highlighted the malicious actions of 30 Chrome extensions downloaded over 260,000 times. These extensions were found to inject iframes to manipulate content and capture browser data, posing as AI assistance tools. Their uniform internal structure suggests they are part of a well-organized scheme.

Advanced Tactics and Targets

One of these extensions was observed rendering a full-screen iframe to a remote domain, allowing attackers to manipulate the user interface directly. This extension and others like it can extract data from active tabs, use triggered voice recognition, and incorporate tracking pixel scripts.

LayerX’s findings indicate that 15 of these extensions specifically target Gmail users, extracting email content and relaying it to third-party servers. Such targeted attacks underline the sophisticated nature of these threats and the need for heightened vigilance among users.

The revelations about these Chrome extensions underscore the urgent requirement for stricter security measures and user awareness to protect personal data online. As investigations continue, users are advised to scrutinize their installed extensions and prioritize their digital safety.

Security Week News Tags:browser security, Chrome extensions, Cybersecurity, data breach, data theft, internet safety, malicious extensions, online privacy, Spyware, user privacy

Post navigation

Previous Post: macOS Users Targeted by Malware via Google Ads
Next Post: ClickFix Attack Uses DNS Hijacking to Deploy Malware

Related Posts

Undetectable Android Spyware Backfires, Leaks 62,000 User Logins Undetectable Android Spyware Backfires, Leaks 62,000 User Logins Security Week News
Over 1 Million Impacted by DaVita Data Breach Over 1 Million Impacted by DaVita Data Breach Security Week News
Storm-2561 Targets VPN Users in Credential Theft Scheme Storm-2561 Targets VPN Users in Credential Theft Scheme Security Week News
Researchers Hack ChatGPT Memories and Web Search Features Researchers Hack ChatGPT Memories and Web Search Features Security Week News
Google’s B Wiz Acquisition Gets EU Nod Google’s $32B Wiz Acquisition Gets EU Nod Security Week News
Vietnamese Hackers Distribute Malware via Fake AI-Themed Websites Vietnamese Hackers Distribute Malware via Fake AI-Themed Websites Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Grafana Labs GitHub Breach: Codebase Compromised by Hackers
  • Grafana Suffers GitHub Token Breach, Faces Extortion
  • Public macOS Kernel Exploit Found on Apple M5 Chip
  • Critical Flaw in Funnel Builder Targets WooCommerce
  • JDownloader Site Incident: Malicious Installers Found

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Grafana Labs GitHub Breach: Codebase Compromised by Hackers
  • Grafana Suffers GitHub Token Breach, Faces Extortion
  • Public macOS Kernel Exploit Found on Apple M5 Chip
  • Critical Flaw in Funnel Builder Targets WooCommerce
  • JDownloader Site Incident: Malicious Installers Found

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark