Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chrome Extensions Exploit User Data for Ad Revenue

Chrome Extensions Exploit User Data for Ad Revenue

Posted on June 14, 2026 By CWS

Recent findings have unveiled a concerning issue involving 152 Chrome extensions that clandestinely monitor user data and fabricate Google search traffic to boost ad revenue. Despite assurances of no data collection, these extensions engage in deceptive practices, raising significant privacy concerns.

Uncovering the Deceptive Extensions

Socket’s Threat Research Team discovered that these extensions, branded as ‘live wallpaper’, are part of a coordinated effort to manipulate new-tab pages. This tactic is used to convert extension-generated visits into seemingly legitimate search traffic, thereby distorting analytics for advertisers and Google itself.

The extensions are developed from a single source code but are disseminated through 38 different publisher accounts and three brands, namely tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com, redirecting to owhit[.]com. Popular themes such as anime and sports wallpapers are used to attract users, with installations estimated at around 105,000, though this figure is likely an underestimation due to Chrome’s reporting methods.

Privacy Misrepresentation

Contrary to their Chrome Web Store privacy declarations, these extensions log extensive user data including IP addresses, browser types, and ISP information. This data is shared with Google AdSense, DoubleClick, and other third-party ad partners, contradicting the stated privacy policies.

A subset of 54 extensions employs a more advanced strategy to impersonate Google search attribution. Upon installation, a background service worker triggers a new tab that appears as if the user accessed it through a genuine Google search, thus corrupting analytics with false traffic data.

Implications and Security Measures

Operating under 38 publisher accounts, the network leverages Google Ad Manager and AdSense accounts to falsely inflate traffic metrics, enhancing perceived credibility to advertisers. The extensions do not insert ads into random websites but rather redirect users to domains like tabplugins[.]com, which are monetized through intensive programmatic advertising.

Researchers have identified specific anti-forensic behaviors, such as the deletion of IndexedDB databases to prevent tracking. This, along with a syntactically flawed bg.js file in some variants, suggests hasty mass production of these extensions, which still manage to pass store reviews.

This operation highlights a significant threat to user privacy and data integrity. For users, the primary risk is involvement in fraudulent traffic measurement rather than direct device compromise. Security teams are advised to look for shared characteristics among these extensions to mitigate the threat.

For more updates on cybersecurity and privacy, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:ad fraud, ad revenue inflation, browser security, Chrome extensions, Chrome Web Store, online privacy, privacy concerns, search traffic manipulation, Socket Research, user data tracking

Post navigation

Previous Post: Maine Suspends Data Breach Portal Due to Fraudulent Reports
Next Post: AI SPERA Presents AITEM at Infosecurity Europe 2026

Related Posts

HydraPWK Penetration Testing OS With Necessary Hacking Tools and Simplified Interface HydraPWK Penetration Testing OS With Necessary Hacking Tools and Simplified Interface Cyber Security News
Critical Axios Flaw Risks Cloud Security Breach Critical Axios Flaw Risks Cloud Security Breach Cyber Security News
Malware Campaign Evades Detection with Advanced Techniques Malware Campaign Evades Detection with Advanced Techniques Cyber Security News
SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations Cyber Security News
Hackers Exploit ComfyUI 700+ AI Image Generation Servers to Deploy Malware Hackers Exploit ComfyUI 700+ AI Image Generation Servers to Deploy Malware Cyber Security News
F5 Breached – Hackers Stole BIG-IP Source Code and Undisclosed Vulnerabilities Data F5 Breached – Hackers Stole BIG-IP Source Code and Undisclosed Vulnerabilities Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ransomware Threat via Microsoft Teams Grows
  • Cantina Secures $8M for Autonomous Security Innovation
  • Microsoft 365 Copilot Vulnerability Exposes Hidden Prompts
  • GitLab Resolves 13 Security Issues Affecting Data and Pipelines
  • Analog Devices Reports Cybersecurity Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ransomware Threat via Microsoft Teams Grows
  • Cantina Secures $8M for Autonomous Security Innovation
  • Microsoft 365 Copilot Vulnerability Exposes Hidden Prompts
  • GitLab Resolves 13 Security Issues Affecting Data and Pipelines
  • Analog Devices Reports Cybersecurity Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark