Browser extensions can read everything you do on a page.
A malicious one doesn’t need to “hack” you. Once installed, it can:
• See every site you visit
• Read what you type (including passwords and 2FA codes)
• Steal session cookies so it can log in as you
• Inject extra scripts or change what the page shows you
• Quietly send the data to a server you never see
The permission prompt usually just says “read and change site data" and most people will click Allow.
Unfortunately, that's already the entire 'attack'.
If you didn’t install it yourself from a source you trust, remove it. And treat any extension that asks for broad access as hostile until proven otherwise.