Did you know browser extensions can steal everything in your browser.
With the permissions you clicked a malicious extension can do these:
— read every page you visit in real time. every banking page, email, document and so on...
— capture your session cookies. the tokens that keep you logged in. steal those and the attacker is logged in as you. no password needed.
— log every keystroke. everything you type into every site.
— inject code into pages you're already on. change what you see. add a fake payment field to a checkout page.
— redirect your traffic through an attacker's server.
— record conversations with AI chatbots.
In April 2026, 108 malicious Chrome extensions were discovered. From Telegram tools to video helpers, productivity add-ons. combined: 20,000 downloads. all sending data to the same backend.
two extensions called Phantom Shuttle had been active since 2017, good nine years secretly routing users' traffic through attacker servers.
one extension stole Meta Business Suite 2FA codes while its privacy policy said the data stayed local.
287 Chrome extensions were caught in February 2026 selling users' complete browsing history to data brokers including Similarweb. legally. buried in the terms.
and the most dangerous version: trusted extensions that turn malicious. a developer's account gets phished. a weaponized update pushes to every existing user who already trusts the add-on. no new install required.
what to do right now:
open your browser extensions.
remove anything you don't actively use.
check what permissions each one has.
An ad blocker doesn't need to "read and change all your data on all websites" to block ads. if it's asking for that, ask why.