chrome.alarms in Manifest V3: background jobs that outlive the service worker
MV3 kills setInterval. Build a Chrome extension background job with chrome.alarms that survives service worker termination — full runnable code, ~20 min.
Insights on browser extension development, security best practices, analytics, and the extension ecosystem.
MV3 kills setInterval. Build a Chrome extension background job with chrome.alarms that survives service worker termination — full runnable code, ~20 min.
The debugger permission gives an extension full Chrome DevTools Protocol access — cookies, keystrokes, any page. Here's what it allows and how to check yours.

A hands-on Manifest V3 tutorial: build a Chrome extension side panel that persists across tabs, then make it per-site. Full runnable code, ~25 minutes.

Are volume booster extensions safe? I break down the permissions, the 1.5M-user sleeper spyware LayerX found, and how to spot a sound booster worth trusting.

Infostealers now bypass Chrome's App-Bound Encryption to raid crypto wallet and password manager extensions. Here's how to check yours and lock them down.

The webNavigation permission lets an extension watch every URL you open live — no host permissions, no injected code. Here's what it sees and how to check.

I compared four popular website blocker extensions on permissions and data sharing. Here's which focus tools keep your browsing private and which don't.

A malicious browser extension can let a remote server open any tab — an ad, a redirect, a fake login. How it works, and how to check and remove them fast.

The GlassWorm takedown by CrowdStrike and Google won't uninstall anything. Here's how to check for malicious browser extensions still sitting in your browser.

The management permission lets a browser extension list every other extension you've installed and toggle them off. Here's what it exposes and how to check.

Screen recorder extensions can reach your camera, mic and every tab. Here's the permission breakdown, the Screencastify webcam bug, and how to record safely.

A fake imToken Chrome extension posed as a color picker and phished seed phrases using invisible homoglyphs. Here's how to check your extensions and stay safe.

The storage permission is the most-requested thing extensions ask for — 62% claim it, with no install warning. Here's what it keeps, where, and how to check.

Is Dark Reader safe? It reads every site you visit — and so do its clones. My security review of Dark Reader, plus the dark mode copies you should avoid.

Socket found 108 Chrome extensions routing logins and live Telegram sessions to a single server. Here's how the campaign worked and how to check your own.

Firefox 153 makes extension file access opt-in from July 21 — even for add-ons you already installed. We found 842 Firefox add-ons that request file:// access.

The proxy permission lets a browser extension reroute all your traffic through servers it controls. Here's what it really allows — and how to check yours.

I compared four web clipper extensions on permissions and data flow. Which read every page you visit, which stay local, and which one I'd actually trust.

Session cookie theft lets attackers skip your login and 2FA. Chrome 146's DBSC binds sessions to your device — but here's the gap extensions still exploit.

The unlimitedStorage permission lets extensions hoard data on your disk with no cap. ~687M users are exposed — and W3C is debating a limit on July 2, 2026.

The activeTab permission lets browser extensions touch the page you're on — only when you click, with no scary install warning. Here's what it grants.

I compared four popular tab manager extensions on permissions, data sync, and privacy. Here's which keep your tab list local and which ship it to the cloud.

A disabled extension can't clear its uninstall URL (setUninstallURL) before removal — the service worker is already dead. Here's why, and the server-side fix.

Two-thirds of Edge extensions and half of Firefox add-ons sit abandoned — no security update in a year. Why stale extensions are risky and how to check yours.

Chrome added a native, promise-based browser.* namespace in 148. Across the 235,887 Chrome extensions we track, here's what it changes — and what to do.

The history permission lets a browser extension read every site you visited — even before you installed it. Here's what it exposes and how to check yours.

Everyone said Chrome's Manifest V2 deadline would kill ad blockers. Here's what the sunset actually stranded — and why Firefox is now the MV2 refuge.

SponsorBlock, Return YouTube Dislike and Enhancer for YouTube checked on permissions, privacy, and how to spot risky clones.

A fake uBlock Origin clone crashed Chrome on purpose, then tricked users into running malware. Here's how to spot the CrashFix trap and check your extensions.

The webRequest permission lets browser extensions watch — and sometimes rewrite — every network request you make. Here's what it really sees and how to check.

chrome.runtime.setUninstallURL opens a page after someone uninstalls your extension. Here's how to turn that uninstall moment into structured churn feedback.

Translation extensions read the full text of every page you translate. I review Google Translate, DeepL, and Immersive Translate on permissions and data flow.
An ACM study found 15.97% of extensions start third-party tracking within 60 seconds. Here's why the permission list never told you, and how to check.

Coupon and cashback extensions watch every site you visit. I review Honey, Rakuten, and Capital One Shopping on permissions, privacy, and the affiliate mess.

I mapped browser extension permissions across 308,210 live listings: 62% claim storage, 7.4% can read every site you visit. Here's what to pause on.
GhostPoster hid malware inside extension icon images for up to five years across Chrome, Firefox, and Edge. Here's how steganography works and what to check.

A privacy researcher says Chrome ships almost no fingerprinting defenses. Here's what sites can really learn about you — and which extensions help.

Screenshot extensions can read every page they capture. Here's the permission breakdown, what the ShotBird hijack revealed, and how to grab screens safely.

Google accidentally exposed an unfixed Chromium service worker flaw that keeps background scripts running after you close the browser. Here's how to stay safe.

The NordVPN extension's new on-device AI voice detector flags deepfake audio without sending anything anywhere. Review of permissions, privacy and alternatives.

A Chrome extension's leaked OAuth tokens pivoted into Vercel's systems. Here's how to audit the extension OAuth grants in your work Google account.

An AI agent extension like OpenAI's Codex asks to 'read all data on all websites.' Here's what it really allows, why agents need it, and how to check yours.

Any zero-permission extension can hijack Claude's AI session and exfiltrate your Gmail or GitHub data. Here's how ClaudeBleed works and how to protect yourself.

LayerX found 82 Chrome extensions legally sell 6.5M users' data via buried privacy policies. Here's how the fine-print loophole works and how to check yours.

24 streaming extensions in the QVI Empire network legally sell your Netflix and Hulu viewing data. Privacy analysis, risk breakdown, and safer alternatives.

Five Chrome extensions stole Workday, NetSuite, and SAP session tokens using three attack vectors. Here's how enterprise teams can check and protect HR access.
The native messaging permission lets browser extensions talk to native apps outside Chrome's sandbox. Here's what it really enables — and how to check yours.
Some ad blockers that sell your data are among the most installed on Chrome. LayerX flagged 12 — here's the breakdown of the worst and safer 2026 alternatives.
A sideloaded browser extension is how UNC6692's SNOWBELT runs inside headless Edge, skipping Web Store review entirely. Here's how to detect it in your org.
AI browser assistant data collection can sweep up your SSN and medical data — UC Davis tested 9 GenAI extensions and found just that. Here's what they access.
Most TikTok downloader extension clones are spyware — StealTok spied on 130K users for up to a year. Here's the security breakdown and safer ways to download.
Chrome extension privilege escalation is real: CVE-2026-0628 let extensions with basic permissions reach your camera, mic, and files via the Gemini panel.
Georgia Tech's Arcanum study found 3,000+ Chrome extensions collect data silently — and none disclose it in their privacy policy. Here's how to check yours.
Firefox built-in VPN is free, capped at 50GB/month and 4 countries. Here's how it compares to Proton VPN, Mullvad, and NordVPN extensions — and which to trust.
GlassWorm malware compromised 72+ Open VSX IDE extensions to drop a Chrome infostealer that steals session cookies via Solana C2. Here's what to check today.
LinkedIn scanned 6,236 Chrome extensions to fingerprint users without consent. Here's how extension fingerprinting works and how to check if you're exposed.
Bitwarden vs 1Password security compared: permissions, audits, vault design, and the SquareX polymorphic spoofing attack Chrome still hasn't patched in 2026.
AI extension incident response, step by step: malicious AI extensions hit 20K+ enterprise tenants with no plan in place. Here's the 60-minute playbook.
The tabs permission lets Chrome extensions log every URL you visit in real time — no history permission needed. Here's what it does and how to audit yours.
Crypto wallet extensions are Torg Grabber's top target — 728 of them. Here's how MetaMask, Phantom, and Trust Wallet hold up on security and what to watch for.
ShadyPanda ran 145 malicious browser extensions on Chrome and Edge for 6 years — from affiliate fraud to keylogging spyware, 4.3M installs. How to check yours.
18 extensions harvested meeting data from 2.2M users on Zoom, Teams, and Meet. Here's how video conferencing extension access works — and how to audit yours.
18 Chrome, Firefox, and Edge meeting extensions with 2.2M installs secretly harvested corporate meeting data. Here's what they did and how to check yours.
Stanley MaaS sold guaranteed Chrome Web Store placement for $6,000. Here's how phishing extensions slip past Google's review — and how to protect yourself.
The scripting permission lets extensions run JavaScript on any page you visit — including your Zoom calls. Here's what that actually means for your privacy.
Incogni's 2026 study flags Grammarly and QuillBot as high-risk AI extensions. Privacy analysis, permission breakdown, and safer alternatives for 2026.
Browser extension host permissions let extensions read and change every website you visit. Here's what that warning actually means and when to be concerned.
The real Proton VPN extension is a standalone browser VPN — with broad permissions by design. Here's what it actually requests and how to spot the fakes.
A zero-permission extension can still drop malware: LayerX Labs showed any extension can silently backdoor your downloads. How to check and stay safe.
The cookies permission lets extensions read, write, and delete cookies — including session tokens. Here's what that means for your accounts and how to check.
Browser extension audit tools compared: LayerX, CrowdStrike Falcon, and Microsoft Defender. What each one does, where it falls short, and which fits your team.
QuickLens got hijacked via an extension ownership transfer to push ClickFix and crypto-stealing malware. Here's how to check your own add-ons are still safe.
Over 200 extensions silently pull email from Gmail and Outlook. Here's how extension email access works and how to check which add-ons can read your inbox.
ETH Zurich broke the zero-knowledge promise in Bitwarden, LastPass, and Dashlane with 25 attacks. See which password manager extensions actually held up best.
Any browser extension can silently inject commands into ChatGPT, Gemini, and Claude. Here's how man-in-the-prompt attacks work and how to keep yourself safe.
AI extension data collection is real: 52% of AI Chrome extensions collect user data. Here's what scripting permissions let them see, and how to check yours.
Is Urban VPN safe? Not after it quietly harvested ChatGPT, Claude and Gemini chats from 8M users. The full review, the timeline, and what to install instead.
A peer-reviewed study found Manifest V3 ad blocking matches MV2 effectiveness. Here's what declarativeNetRequest really changes if you build content filters.
Security researchers exposed 300+ malicious Chrome extensions with 37.4M downloads stealing data, credentials, and emails. Here's how to protect yourself.
WXT, Plasmo, CRXJS, Extension.js, and Bedframe — five browser extension frameworks compared by build time, bundle size, and maintenance health in 2026.
Mozilla now requires all Firefox extensions to declare data collection in manifest.json. Here's exactly how to implement data_collection_permissions correctly.
A researcher found 287 Chrome extensions allegedly leaking browsing history to third-party companies. Here's how it works and how to check yours.
30 fake AI Chrome extensions caught stealing credentials and Gmail data from 300K users. Here's how to check if you're affected and protect yourself.
17 malicious sleeper extensions found across Firefox, Chrome, and Edge with 840K downloads. They hid malware in images for up to 5 years undetected.