Back to articles

Chrome Web Store's new policy rules: how to check your browser extensions

The August 2026 Chrome Web Store policy update bans AI-jailbreak extensions and tightens data rules. Here's what changed and how to check your own extensions.

Maxim Kosterin
10 min read
A hairline storefront with a scalloped awning and a small puzzle-piece sign hanging beside it; a soft orange watercolor wash fills the open doorway and a few drops spill past the threshold onto the ground line.
A hairline storefront with a scalloped awning and a small puzzle-piece sign hanging beside it; a soft orange watercolor wash fills the open doorway and a few drops spill past the threshold onto the ground line.

On August 1, Google began enforcing a Chrome Web Store policy update that changes what extensions are allowed to collect. No keynote, no countdown timer — just a blog post published a month earlier and an enforcement date. If you install browser extensions, two of the changes affect you directly: any data an extension collects must now be "strictly necessary" to its disclosed single purpose, and the store has a new, explicit rule against extensions built to circumvent the safeguards of AI services.

I've spent this whole year writing about the gap between what extensions promise and what they do. This update moves part of that question into the store's own rulebook: does the extension need this data to do its job? So here's what changed, which loopholes it narrows, and — because policy is just text until somebody enforces it — the parts of the problem it leaves untouched.

What changed in the Chrome Web Store policy on August 1

The update, published July 1, 2026 on the Chrome for Developers blog, has four pieces:

1. Data collection must be "strictly necessary." Under the Limited Use policy, any user data an extension collects has to be strictly necessary to its disclosed single purpose, and collecting data for other purposes is prohibited. As I read it, an ad blocker that also logs your browsing history to resell it no longer has policy cover. The Limited Use page adds that collecting web browsing activity is prohibited except where a user-facing feature described prominently on the listing requires it.

2. Disclosure has to be prominent, and it has to follow changes. The Disclosure Requirements policy now says all data collection must be prominently disclosed regardless of whether it's closely related to the extension's purpose, and developers must proactively disclose to users if their data handling practices change after installation. The policy page puts it plainly: different data practices after installation must be prominently disclosed. Quietly editing a privacy policy page doesn't look like prominent disclosure to me. This is the sleeper change of the whole update, and I'll come back to it.

3. A new rule against circumventing AI safeguards. The Malicious and Prohibited Products policy gets a rule against extensions "designed to circumvent safety guardrails, usage restrictions, or other protective measures implemented by AI-powered services," in Google's words. Google calls it a new policy, and it's the first one I've seen written for AI-service bypass tools specifically.

4. Real-money prediction markets are out. The Regulated Goods and Services policy now names predictive markets explicitly: extensions that facilitate real-money transactions on predictive outcomes aren't allowed.

Enforcement began August 1. Google's announcement says only that extensions found out of compliance after that date "may face enforcement action." It doesn't list the actions, and it doesn't say whether a takedown reaches copies that are already installed. LayerX notes that extensions pulled from the store can stay active in browsers that already have them. A listing disappearing from the store is not the same as the extension disappearing from yours.

The loophole this narrows

In May I wrote up LayerX Security's findings on 82 extensions whose own privacy policies say they sell user data — at least 6.5 million users between them, per LayerX. The mechanics were simple: bury a "we may sell" clause in a privacy policy nobody reads, collect consent at install, and never mention it again. LayerX also cites its 2026 enterprise report for a number that explains why this works: 71% of all Chrome Web Store extensions don't publish a privacy policy at all.

The disclosure-on-change requirement speaks directly to the second half of that playbook. "May sell" clauses work because consent is captured once, at install, and then stretched over everything the extension does later. If an extension widens its data practices after you've installed it, the policy now says users must be told — proactively, not through a diff on a legal page nobody checks.

The "strictly necessary" language handles the other half: data minimization. It turns what used to be a vibe judgment into a question with a yes-or-no answer. Does this data serve the extension's declared single purpose? That's the question I ask when I read an extension's permissions.

Extenshi's scanner works statically — it reads the manifest and the code, and it doesn't see what an extension sends at runtime — so what it can flag is the mismatch you can see on paper, like a broad access request on a narrow tool. Nice to see the store's rulebook ask the same thing.

One honest caveat: Google's announcement says nothing about cleaning up extensions that are already installed with broad, vague disclosures. Presumably the rules bite the next time those extensions update, or the next time someone reports them. And "may sell" clauses aren't the only gap: Georgia Tech's Arcanum study, which I covered in the privacy policy gap explained, found 3,000+ extensions collecting data their privacy policies never disclose.

The AI-jailbreak rule

AI extensions are where a lot of this year's security research has pointed. LayerX's 2026 Browser Extension Security Report found that AI extensions are 60% more likely than the average extension to contain a known CVE, and about six times more likely to have expanded their permissions over the past year. I went through those numbers in my review of Chrome's built-in Gemini against AI extensions. I've covered the incident stream all year: 30 fake AI extensions reported stealing credentials and Gmail data, and extensions that can drive an AI assistant with synthetic clicks.

The new rule is narrower than that incident stream. It targets extensions built to get around the safeguards or usage limits of AI services — jailbreak tools. Google doesn't say in the announcement how it will decide what counts, so expect some gray areas.

The risk on your side is one I can reason about without any new data. Anything that sits between you and an AI service — to unlock it, relay it, or rewrite your prompts — can read what you type there, because it needs access to that page to do its job.

With a jailbreak tool, you're trusting its developer with that access. I'd expect takedowns in this category over the coming months. If you have one installed, I wouldn't wait for the store to act.

What the new rules don't fix

I don't want to oversell this. A policy update changes the rulebook, not who finds the problems. Three well-documented failure modes survive it intact.

Enforcement still leans on outside reports. In July 2025, BleepingComputer reported on almost a dozen malicious extensions with 1.7 million downloads between them. Koi Security found them and reported them to Google, and Google later confirmed to BleepingComputer that they'd been removed. I don't see anything in the August update that changes that sequence: researchers find it first, the store acts second. If anything, the new rules likely mean more of what's already live is technically out of compliance.

Clean-at-review, dirty-after-update still works. Shipping a clean version through review and adding the payload in a later update is a well-worn trick. I broke down a recent case in my piece on extension update hijacking. According to Netskope Threat Labs, an extension pulled in January for scraping AI chats was listed again, shipped a clean version 1.7.2.0 in late July, and about two weeks later version 1.7.3.0 added 21 lines that open an affiliate link on every update. Nothing in the August update changes that timeline — it only adds more categories of post-update behavior that count as violations.

Takedowns create room for clones. When an extension you rely on disappears, you go looking for a replacement, and that's where lookalikes get installed. The Manifest V2 delisting is the biggest recent example, and I wrote up how to replace a delisted extension without installing a clone last month. A stricter policy means more takedowns, and more takedowns plausibly mean more of that. The rules don't address that second-order effect.

How to check your extensions against the new rules

Here's the audit I'd run this week, in order of payoff:

1. Re-read the privacy practices of your five most-used extensions. Open each listing's privacy section, not the marketing text. Under the new rules that disclosure is something the store can hold the developer to, so read it as a promise. If it says the extension sells or shares your data, you have your answer.

2. Treat silent practice changes as a red flag — and report them. If an extension you use starts collecting something new and nobody told you, that looks like a violation of the new disclosure requirement. On the listing, click Flag Issue at the bottom left, fill out the form and submit it. Google documents the steps on its Chrome Web Store Help page.

3. Remove any AI "unlocker" or jailbreak extension yourself. The rule says they're not allowed, but nothing in the announcement promises they'll vanish from your browser when the listing goes. Whatever such an extension could read on those pages, it can read today.

4. Check for stale and cloned entries. If you installed something months ago and forgot it, verify the listing still exists and the publisher hasn't changed. Replacements for delisted extensions are where clones tend to hide.

5. Scan the whole list at once. Manual audits miss the extension you forgot you had, and that's usually the interesting one. npx @extenshi/guard list prints every extension installed across your browsers, no account needed, and npx @extenshi/guard scan checks them against the Extenshi catalog and gives a verdict for each (free account required, docs here). For a single extension, paste its store URL into the Extenshi checker for its safety score and permissions breakdown, or look it up in the full catalog before you install it.

The bottom line

The August 2026 update is a real tightening of the Chrome Web Store's rulebook: data minimization with a clear test, disclosure that has to follow changes, and an explicit rule aimed at AI-service bypass tools. It narrows the "legally selling your data" playbook.

But a rulebook is not a security team. Enforcement still waits for reports, updates still land after review, and takedowns still spawn clones. The gap between policy and practice is where you should keep operating — audit what's installed, watch for changes, and don't assume that being listed in the store means an extension is clean.

See what your extensions can access → Scan Your Extensions

Sources


This article is based on publicly available security research and news reporting. Extenshi does not independently verify all claims made by third-party researchers. References to specific companies or products reflect the findings of cited sources and do not constitute accusations of intentional wrongdoing. If you believe any information is inaccurate, please contact us at [email protected].

Related Articles