
2FA authenticator extensions reviewed: where your TOTP seeds actually live
2FA browser extensions compared: where Authenticator, 2FAS and password-manager TOTP keep your seeds — and how the fake authenticator clones steal them.
69 articles found

2FA browser extensions compared: where Authenticator, 2FAS and password-manager TOTP keep your seeds — and how the fake authenticator clones steal them.

A Chrome extension pulled in January is back — and shipped its payload two weeks after a clean release. How update-time malware works, and how to check yours.

CWS API V1 dies October 15. Chrome 154 adds chrome.publicSuffix. Edge MV2 and Firefox's two-week train are background.

A hands-on Manifest V3 tutorial: use the chrome.management API and Chrome's own permission warnings to audit every extension installed. Full runnable code.

Your content script runs once on YouTube and never again. Fix Chrome extension SPA navigation with webNavigation — or without a new permission. Full MV3 code.

Edge starts phasing out MV2. Firefox 155 goes fortnightly. Chrome 153 binds protocol handlers to the extension lifetime.

chrome.scripting.executeScript end to end: inject on click with activeTab, pass args safely, and choose ISOLATED or MAIN world. Full MV3 code, ~25 min.

Replacing your new tab page takes no permission at all. Here's what a new tab override extension can really see, when it's fine, and how to check yours.

Chrome extension optional permissions, end to end: install with no warning, then request topSites and a single host at runtime. Full MV3 code, ~25 minutes.

Firefox 154 ships the sandbox manifest key. Chrome 153 blocks user scripts from privileged renderers and asks you to reload after site-access changes.

Build a Manifest V3 Chrome extension that blocks trackers and strips tracking parameters with declarativeNetRequest — full runnable code, ~30 minutes.

The downloads permission lets an extension read every file you've downloaded, write new ones, and hide the download UI. Here's what it allows and how to check.

MV3 service workers have no DOM. Build a Chrome extension that parses HTML and writes to the clipboard from an offscreen document — runnable code, ~25 min.

AMO now builds Firefox add-ons from source. Chrome 152 beta brings a badge cap and a tighter browser namespace.

MV3 kills setInterval. Build a Chrome extension background job with chrome.alarms that survives service worker termination — full runnable code, ~20 min.

The debugger permission gives an extension full Chrome DevTools Protocol access — cookies, keystrokes, any page. Here's what it allows and how to check yours.

A hands-on Manifest V3 tutorial: build a Chrome extension side panel that persists across tabs, then make it per-site. Full runnable code, ~25 minutes.

Chrome 151 deletes every remaining MV2 flag. Messaging gets structured clone. setBadgeText is capped at 100 bytes.

The webNavigation permission lets an extension watch every URL you open live — no host permissions, no injected code. Here's what it sees and how to check.

A malicious browser extension can let a remote server open any tab — an ad, a redirect, a fake login. How it works, and how to check and remove them fast.

The management permission lets a browser extension list every other extension you've installed and toggle them off. Here's what it exposes and how to check.

Screen recorder extensions can reach your camera, mic and every tab. Here's the permission breakdown, the Screencastify webcam bug, and how to record safely.

A fake imToken Chrome extension posed as a color picker and phished seed phrases using invisible homoglyphs. Here's how to check your extensions and stay safe.

The storage permission is the most-requested thing extensions ask for — 62% claim it, with no install warning. Here's what it keeps, where, and how to check.

Socket found 108 Chrome extensions routing logins and live Telegram sessions to a single server. Here's how the campaign worked and how to check your own.

The proxy permission lets a browser extension reroute all your traffic through servers it controls. Here's what it really allows — and how to check yours.

Session cookie theft lets attackers skip your login and 2FA. Chrome 146's DBSC binds sessions to your device — but here's the gap extensions still exploit.

The unlimitedStorage permission lets extensions hoard data on your disk with no cap. ~687M users are exposed — and W3C is debating a limit on July 2, 2026.

The activeTab permission lets browser extensions touch the page you're on — only when you click, with no scary install warning. Here's what it grants.

A disabled extension can't clear its uninstall URL (setUninstallURL) before removal — the service worker is already dead. Here's why, and the server-side fix.

Two-thirds of Edge extensions and half of Firefox add-ons sit abandoned — no security update in a year. Why stale extensions are risky and how to check yours.

Chrome added a native, promise-based browser.* namespace in 148. Across the 235,887 Chrome extensions we track, here's what it changes — and what to do.

The history permission lets a browser extension read every site you visited — even before you installed it. Here's what it exposes and how to check yours.

Everyone said Chrome's Manifest V2 deadline would kill ad blockers. Here's what the sunset actually stranded — and why Firefox is now the MV2 refuge.

SponsorBlock, Return YouTube Dislike and Enhancer for YouTube checked on permissions, privacy, and how to spot risky clones.

A fake uBlock Origin clone crashed Chrome on purpose, then tricked users into running malware. Here's how to spot the CrashFix trap and check your extensions.

The webRequest permission lets browser extensions watch — and sometimes rewrite — every network request you make. Here's what it really sees and how to check.

chrome.runtime.setUninstallURL opens a page after someone uninstalls your extension. Here's how to turn that uninstall moment into structured churn feedback.
An ACM study found 15.97% of extensions start third-party tracking within 60 seconds. Here's why the permission list never told you, and how to check.
GhostPoster hid malware inside extension icon images for up to five years across Chrome, Firefox, and Edge. Here's how steganography works and what to check.

Screenshot extensions can read every page they capture. Here's the permission breakdown, what the ShotBird hijack revealed, and how to grab screens safely.

The NordVPN extension's new on-device AI voice detector flags deepfake audio without sending anything anywhere. Review of permissions, privacy and alternatives.

An AI agent extension like OpenAI's Codex asks to 'read all data on all websites.' Here's what it really allows, why agents need it, and how to check yours.

Any zero-permission extension can hijack Claude's AI session and exfiltrate your Gmail or GitHub data. Here's how ClaudeBleed works and how to protect yourself.

LayerX found 82 Chrome extensions legally sell 6.5M users' data via buried privacy policies. Here's how the fine-print loophole works and how to check yours.

24 streaming extensions in the QVI Empire network legally sell your Netflix and Hulu viewing data. Privacy analysis, risk breakdown, and safer alternatives.

Five Chrome extensions stole Workday, NetSuite, and SAP session tokens using three attack vectors. Here's how enterprise teams can check and protect HR access.
The native messaging permission lets browser extensions talk to native apps outside Chrome's sandbox. Here's what it really enables — and how to check yours.
Some ad blockers that sell your data are among the most installed on Chrome. LayerX flagged 12 — here's the breakdown of the worst and safer 2026 alternatives.
AI browser assistant data collection can sweep up your SSN and medical data — UC Davis tested 9 GenAI extensions and found just that. Here's what they access.
Chrome extension privilege escalation is real: CVE-2026-0628 let extensions with basic permissions reach your camera, mic, and files via the Gemini panel.
Georgia Tech's Arcanum study found 3,000+ Chrome extensions collect data silently — and none disclose it in their privacy policy. Here's how to check yours.
GlassWorm malware compromised 72+ Open VSX IDE extensions to drop a Chrome infostealer that steals session cookies via Solana C2. Here's what to check today.
LinkedIn scanned 6,236 Chrome extensions to fingerprint users without consent. Here's how extension fingerprinting works and how to check if you're exposed.
Bitwarden vs 1Password security compared: permissions, audits, vault design, and the SquareX polymorphic spoofing attack Chrome still hasn't patched in 2026.
AI extension incident response, step by step: malicious AI extensions hit 20K+ enterprise tenants with no plan in place. Here's the 60-minute playbook.
The tabs permission lets Chrome extensions log every URL you visit in real time — no history permission needed. Here's what it does and how to audit yours.
ShadyPanda ran 145 malicious browser extensions on Chrome and Edge for 6 years — from affiliate fraud to keylogging spyware, 4.3M installs. How to check yours.
18 Chrome, Firefox, and Edge meeting extensions with 2.2M installs secretly harvested corporate meeting data. Here's what they did and how to check yours.
The scripting permission lets extensions run JavaScript on any page you visit — including your Zoom calls. Here's what that actually means for your privacy.
Incogni's 2026 study flags Grammarly and QuillBot as high-risk AI extensions. Privacy analysis, permission breakdown, and safer alternatives for 2026.
Browser extension host permissions let extensions read and change every website you visit. Here's what that warning actually means and when to be concerned.
A zero-permission extension can still drop malware: LayerX Labs showed any extension can silently backdoor your downloads. How to check and stay safe.
The cookies permission lets extensions read, write, and delete cookies — including session tokens. Here's what that means for your accounts and how to check.
QuickLens got hijacked via an extension ownership transfer to push ClickFix and crypto-stealing malware. Here's how to check your own add-ons are still safe.
AI extension data collection is real: 52% of AI Chrome extensions collect user data. Here's what scripting permissions let them see, and how to check yours.
Is Urban VPN safe? Not after it quietly harvested ChatGPT, Claude and Gemini chats from 8M users. The full review, the timeline, and what to install instead.
A peer-reviewed study found Manifest V3 ad blocking matches MV2 effectiveness. Here's what declarativeNetRequest really changes if you build content filters.
A researcher found 287 Chrome extensions allegedly leaking browsing history to third-party companies. Here's how it works and how to check yours.