Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Data Breach by Over 300 Chrome Extensions Uncovered

Data Breach by Over 300 Chrome Extensions Uncovered

Posted on February 14, 2026 By CWS

More than 300 Chrome extensions have been identified as threats to user privacy, leaking or stealing sensitive browser data. Security researchers have sounded the alarm over these malicious extensions that have been installed by millions of users worldwide, compromising their data security.

Unmasking the Threat

In a comprehensive study analyzing network traffic from Chrome extensions, researchers uncovered 287 applications that transmit user browsing history and search engine results. The findings reveal that some extensions inadvertently expose data to unsecured networks, while others deliberately send information to data collection servers, either for profit or with harmful intentions.

The scale of this issue is significant, with over 37.4 million users affected. Of these, approximately 27.2 million have installed 153 extensions confirmed to leak browsing history upon installation. The investigation led by researcher Q Continuum also flagged over 200 additional extensions that share author details with the offending apps, raising suspicion about their integrity.

Connections and Implications

Q Continuum’s research suggests that these malicious activities might be orchestrated by data brokers, rather than the extension developers themselves. The extensions have been linked to 32 different entities, with ties to known spyware distributors, indicating a potentially coordinated effort to monetize stolen user data.

In parallel, a report by LayerX has highlighted the malicious actions of 30 Chrome extensions downloaded over 260,000 times. These extensions were found to inject iframes to manipulate content and capture browser data, posing as AI assistance tools. Their uniform internal structure suggests they are part of a well-organized scheme.

Advanced Tactics and Targets

One of these extensions was observed rendering a full-screen iframe to a remote domain, allowing attackers to manipulate the user interface directly. This extension and others like it can extract data from active tabs, use triggered voice recognition, and incorporate tracking pixel scripts.

LayerX’s findings indicate that 15 of these extensions specifically target Gmail users, extracting email content and relaying it to third-party servers. Such targeted attacks underline the sophisticated nature of these threats and the need for heightened vigilance among users.

The revelations about these Chrome extensions underscore the urgent requirement for stricter security measures and user awareness to protect personal data online. As investigations continue, users are advised to scrutinize their installed extensions and prioritize their digital safety.

Security Week News Tags:browser security, Chrome extensions, Cybersecurity, data breach, data theft, internet safety, malicious extensions, online privacy, Spyware, user privacy

Post navigation

Previous Post: macOS Users Targeted by Malware via Google Ads
Next Post: ClickFix Attack Uses DNS Hijacking to Deploy Malware

Related Posts

isVerified Emerges From Stealth With Voice Deepfake Detection Apps isVerified Emerges From Stealth With Voice Deepfake Detection Apps Security Week News
Ransomware Groups May Shift Back to Encryption Strategies Ransomware Groups May Shift Back to Encryption Strategies Security Week News
Police in Brazil Arrest a Suspect Over 0M Banking Hack Police in Brazil Arrest a Suspect Over $100M Banking Hack Security Week News
Hackers Targeting Cisco Unified CM Zero-Day  Hackers Targeting Cisco Unified CM Zero-Day  Security Week News
Zania Raises  Million for AI-Powered GRC Platform Zania Raises $18 Million for AI-Powered GRC Platform Security Week News
Over 300,000 Individuals Impacted by Vitas Hospice Data Breach Over 300,000 Individuals Impacted by Vitas Hospice Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ClickFix Attack Uses DNS Hijacking to Deploy Malware
  • Data Breach by Over 300 Chrome Extensions Uncovered
  • macOS Users Targeted by Malware via Google Ads
  • Critical OpenSea Exploit Chain for Sale on Dark Web
  • Critical SQL Injection Flaw in Microsoft Manager Alerted by CISA

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ClickFix Attack Uses DNS Hijacking to Deploy Malware
  • Data Breach by Over 300 Chrome Extensions Uncovered
  • macOS Users Targeted by Malware via Google Ads
  • Critical OpenSea Exploit Chain for Sale on Dark Web
  • Critical SQL Injection Flaw in Microsoft Manager Alerted by CISA

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News