
Extension Pulse, week of August 24: CWS API V1 dies October 15, and Chrome is giving you the Public Suffix List
CWS API V1 dies October 15. Chrome 154 adds chrome.publicSuffix. Edge MV2 and Firefox's two-week train are background.
40 articles found

CWS API V1 dies October 15. Chrome 154 adds chrome.publicSuffix. Edge MV2 and Firefox's two-week train are background.

Cookie extensions touch your session tokens and every site you visit. I compared Cookie-Editor, Cookie AutoDelete and the banner blockers on who owns them.

Edge starts phasing out MV2. Firefox 155 goes fortnightly. Chrome 153 binds protocol handlers to the extension lifetime.

Replacing your new tab page takes no permission at all. Here's what a new tab override extension can really see, when it's fine, and how to check yours.

Firefox 154 ships the sandbox manifest key. Chrome 153 blocks user scripts from privileged renderers and asks you to reload after site-access changes.

Mozilla's W3C proposal puts AI agent permissions on the browser's extension model. I counted that model at scale: 300,503 extensions, 12,277 already pulled.

OpenAI's Black Hat 2026 talk showed autonomous AI agents coordinating attacks and breaching Hugging Face — the security debt they walked through is yours too.

The downloads permission lets an extension read every file you've downloaded, write new ones, and hide the download UI. Here's what it allows and how to check.

AMO now builds Firefox add-ons from source. Chrome 152 beta brings a badge cap and a tighter browser namespace.

The debugger permission gives an extension full Chrome DevTools Protocol access — cookies, keystrokes, any page. Here's what it allows and how to check yours.

Chrome 151 deletes every remaining MV2 flag. Messaging gets structured clone. setBadgeText is capped at 100 bytes.

The webNavigation permission lets an extension watch every URL you open live — no host permissions, no injected code. Here's what it sees and how to check.

CWS data-minimisation rules enforce August 1. Firefox 153 ships tomorrow. Firefox and Safari just lined up behind COOP/COEP for extension pages.

The management permission lets a browser extension list every other extension you've installed and toggle them off. Here's what it exposes and how to check.

Chrome Web Store yanks remaining MV2 listings on August 31. AI-agent permissions landed at W3C. The MV2 preference storage is already deleted in Chromium.

The storage permission is the most-requested thing extensions ask for — 62% claim it, with no install warning. Here's what it keeps, where, and how to check.

Chrome Web Store opens to 120+ countries, Firefox 153 ESR is two weeks out, and W3C still can't agree a cap on unlimitedStorage. Here's what actually matters.

The proxy permission lets a browser extension reroute all your traffic through servers it controls. Here's what it really allows — and how to check yours.

The unlimitedStorage permission lets extensions hoard data on your disk with no cap. ~687M users are exposed — and W3C is debating a limit on July 2, 2026.

The activeTab permission lets browser extensions touch the page you're on — only when you click, with no scary install warning. Here's what it grants.

A disabled extension can't clear its uninstall URL (setUninstallURL) before removal — the service worker is already dead. Here's why, and the server-side fix.

The history permission lets a browser extension read every site you visited — even before you installed it. Here's what it exposes and how to check yours.

The webRequest permission lets browser extensions watch — and sometimes rewrite — every network request you make. Here's what it really sees and how to check.

chrome.runtime.setUninstallURL opens a page after someone uninstalls your extension. Here's how to turn that uninstall moment into structured churn feedback.
An ACM study found 15.97% of extensions start third-party tracking within 60 seconds. Here's why the permission list never told you, and how to check.

I mapped browser extension permissions across 308,210 live listings: 62% claim storage, 7.4% can read every site you visit. Here's what to pause on.

A privacy researcher says Chrome ships almost no fingerprinting defenses. Here's what sites can really learn about you — and which extensions help.

LayerX found 82 Chrome extensions legally sell 6.5M users' data via buried privacy policies. Here's how the fine-print loophole works and how to check yours.
The native messaging permission lets browser extensions talk to native apps outside Chrome's sandbox. Here's what it really enables — and how to check yours.
AI browser assistant data collection can sweep up your SSN and medical data — UC Davis tested 9 GenAI extensions and found just that. Here's what they access.
Georgia Tech's Arcanum study found 3,000+ Chrome extensions collect data silently — and none disclose it in their privacy policy. Here's how to check yours.
LinkedIn scanned 6,236 Chrome extensions to fingerprint users without consent. Here's how extension fingerprinting works and how to check if you're exposed.
The tabs permission lets Chrome extensions log every URL you visit in real time — no history permission needed. Here's what it does and how to audit yours.
18 extensions harvested meeting data from 2.2M users on Zoom, Teams, and Meet. Here's how video conferencing extension access works — and how to audit yours.
The scripting permission lets extensions run JavaScript on any page you visit — including your Zoom calls. Here's what that actually means for your privacy.
Browser extension host permissions let extensions read and change every website you visit. Here's what that warning actually means and when to be concerned.
The cookies permission lets extensions read, write, and delete cookies — including session tokens. Here's what that means for your accounts and how to check.
Browser extension audit tools compared: LayerX, CrowdStrike Falcon, and Microsoft Defender. What each one does, where it falls short, and which fits your team.
Over 200 extensions silently pull email from Gmail and Outlook. Here's how extension email access works and how to check which add-ons can read your inbox.
Any browser extension can silently inject commands into ChatGPT, Gemini, and Claude. Here's how man-in-the-prompt attacks work and how to keep yourself safe.