Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chrome Extensions Exploit User Data for Ad Revenue

Chrome Extensions Exploit User Data for Ad Revenue

Posted on June 14, 2026 By CWS

Recent findings have unveiled a concerning issue involving 152 Chrome extensions that clandestinely monitor user data and fabricate Google search traffic to boost ad revenue. Despite assurances of no data collection, these extensions engage in deceptive practices, raising significant privacy concerns.

Uncovering the Deceptive Extensions

Socket’s Threat Research Team discovered that these extensions, branded as ‘live wallpaper’, are part of a coordinated effort to manipulate new-tab pages. This tactic is used to convert extension-generated visits into seemingly legitimate search traffic, thereby distorting analytics for advertisers and Google itself.

The extensions are developed from a single source code but are disseminated through 38 different publisher accounts and three brands, namely tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com, redirecting to owhit[.]com. Popular themes such as anime and sports wallpapers are used to attract users, with installations estimated at around 105,000, though this figure is likely an underestimation due to Chrome’s reporting methods.

Privacy Misrepresentation

Contrary to their Chrome Web Store privacy declarations, these extensions log extensive user data including IP addresses, browser types, and ISP information. This data is shared with Google AdSense, DoubleClick, and other third-party ad partners, contradicting the stated privacy policies.

A subset of 54 extensions employs a more advanced strategy to impersonate Google search attribution. Upon installation, a background service worker triggers a new tab that appears as if the user accessed it through a genuine Google search, thus corrupting analytics with false traffic data.

Implications and Security Measures

Operating under 38 publisher accounts, the network leverages Google Ad Manager and AdSense accounts to falsely inflate traffic metrics, enhancing perceived credibility to advertisers. The extensions do not insert ads into random websites but rather redirect users to domains like tabplugins[.]com, which are monetized through intensive programmatic advertising.

Researchers have identified specific anti-forensic behaviors, such as the deletion of IndexedDB databases to prevent tracking. This, along with a syntactically flawed bg.js file in some variants, suggests hasty mass production of these extensions, which still manage to pass store reviews.

This operation highlights a significant threat to user privacy and data integrity. For users, the primary risk is involvement in fraudulent traffic measurement rather than direct device compromise. Security teams are advised to look for shared characteristics among these extensions to mitigate the threat.

For more updates on cybersecurity and privacy, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:ad fraud, ad revenue inflation, browser security, Chrome extensions, Chrome Web Store, online privacy, privacy concerns, search traffic manipulation, Socket Research, user data tracking

Post navigation

Previous Post: Maine Suspends Data Breach Portal Due to Fraudulent Reports
Next Post: AI SPERA Presents AITEM at Infosecurity Europe 2026

Related Posts

Microsoft SQL Server Vulnerability Let Attackers Escalate Privileges Microsoft SQL Server Vulnerability Let Attackers Escalate Privileges Cyber Security News
Google Announces Public Preview of Alert Triage and Investigation Agent used in Google Security Operations Google Announces Public Preview of Alert Triage and Investigation Agent used in Google Security Operations Cyber Security News
Notepad++ DLL Hijacking Vulnerability Let Attackers Execute Malicious Code Notepad++ DLL Hijacking Vulnerability Let Attackers Execute Malicious Code Cyber Security News
Critical ConnectWise ScreenConnect Flaw Under Exploitation Critical ConnectWise ScreenConnect Flaw Under Exploitation Cyber Security News
Ransomware Disrupts BridgePay’s Nationwide Payment Processing Ransomware Disrupts BridgePay’s Nationwide Payment Processing Cyber Security News
Weedhack Malware Poses Threat to Minecraft Users Weedhack Malware Poses Threat to Minecraft Users Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Resolves 13 Security Issues Affecting Data and Pipelines
  • Analog Devices Reports Cybersecurity Breach
  • Silver Fox’s New BYOVD Attack Targets Japanese Industry
  • AtlasRAT Malware Hidden in Fake Flash Installer
  • Data Center Vulnerabilities Expose Critical Systems to Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Resolves 13 Security Issues Affecting Data and Pipelines
  • Analog Devices Reports Cybersecurity Breach
  • Silver Fox’s New BYOVD Attack Targets Japanese Industry
  • AtlasRAT Malware Hidden in Fake Flash Installer
  • Data Center Vulnerabilities Expose Critical Systems to Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark