Security researchers just flagged more than 100 Chrome extensions quietly stealing browsing data, session cookies, saved passwords, and even chat tokens from apps like Telegram. If your browser is full of extensions you installed months ago and forgot about, that headline stings. Here’s the checklist to find out if one of yours is guilty.
What Happened, in Plain English
BleepingComputer and gHacks both reported on a wave of malicious Chrome extensions. Some posed as ad blockers, VPN tools, and productivity add-ons. Each one got broad permissions. Then it used that access to read page content, capture session cookies, and quietly send your data somewhere it shouldn’t go. Extensions run with elevated access inside the browser, so they don’t need to trick you twice. Once installed and approved, they can run silently for months with zero visible symptoms.
You don’t need to know the exact names on that list to protect yourself. The permissions and behavior patterns below are the real tell. They apply to any malicious extension, past or future.
Quick Diagnosis
Before doing a deep audit, run this 2-minute gut check:
- Open
chrome://extensionsand count how many extensions you actually recognize installing yourself. - Look for any extension with a generic name, a stock-icon logo, or a description that doesn’t match what you remember it doing.
- Check whether any extension is disabled but still listed. That’s sometimes a leftover from Chrome auto-disabling something it flagged as harmful.
- If Chrome shows a banner saying it disabled an extension for policy or safety reasons, take that seriously. Click it before doing anything else.
If any of those raise a flag, move straight to the full audit below.
Open Chrome’s Extension Manager
- Launch Chrome.
- Type
chrome://extensionsinto the address bar and pressEnter. - Alternatively, click the puzzle-piece icon in the toolbar, then select Manage extensions.


Common Issues
Problem: Not Sure What an Extension Can Actually See
Symptoms:
- You installed the extension a long time ago and forgot what it does
- The extension name sounds harmless (calculator, wallpaper, screenshot tool) but you’re not sure what it accesses
- You want to confirm site access before trusting it with anything sensitive
Why it happens: Chrome doesn’t surface permission details on the main list page. You have to open each extension individually to see what it’s allowed to touch.
Fix:
- On
chrome://extensions, click Details under the extension you want to check. - Scroll to the Permissions section to see exactly what it can do. Look for language like “Read and change all your data on all websites.”
- Scroll to Site access and check whether it’s set to On all sites, On specific sites, or On click.
- If it’s set to On all sites and doesn’t need to be, change it to On specific sites or On click to limit exposure without removing the extension entirely.

Tip: A password manager or ad blocker legitimately needs “all sites” access to work. A wallpaper changer or calculator doesn’t. Judge the permission against the extension’s actual job, rather than whether it sounds scary.
Problem: You Can’t Tell If an Extension Is Legitimately Owned
Symptoms:
- The extension has years of good reviews but recently started behaving oddly
- You don’t recognize the developer name in the extension’s details
- The extension update happened without you noticing a new feature or UI change to explain it
Why it happens: Extension ownership changes hands more often than people realize. A popular extension gets sold. The new owner pushes an update that adds tracking or data-harvesting code. Chrome doesn’t warn you when this happens. It just installs the update automatically.
Fix:
- On the extension’s Details page in
chrome://extensions, note the extension’s name and version number. - Open the Chrome Web Store and search for the same extension.
- On the listing page, check the developer/publisher name under Additional Information.
- Scroll through recent reviews. A sudden cluster of one-star reviews mentioning redirects, pop-ups, or “this used to be fine” comments is a strong signal. It usually means the extension changed hands or got compromised.

Problem: An Extension Has Broad Permissions It Doesn’t Need
Symptoms:
- A simple utility extension (screenshot tool, note-taking app, theme) requests access to all websites
- The extension asks for permissions unrelated to its stated purpose, like reading clipboard content or managing cookies
- You installed it for one specific task but it wants far more access than that task requires
Why it happens: This is the single biggest red flag from the recent malicious extension wave. Broad host permissions (“Read and change all your data on all websites”) paired with a narrow, unrelated purpose is a mismatch. Legitimate extensions request only what they need.
Fix:
- Open Details for the extension in
chrome://extensions. - Compare the Permissions list against what the extension is supposed to do.
- If a note-taking extension requests “Read your browsing history” or “Manage your downloads,” that’s a mismatch worth acting on.
- When in doubt, remove it. See the removal steps below.
Tip: Ask yourself one question for every permission: “Does this extension’s core feature require this?” If you can’t answer yes, it shouldn’t have that access.
Problem: You Need to Remove a Suspicious Extension
Symptoms:
- You’ve confirmed red flags (broad permissions, ownership change, bad reviews) on an installed extension
- Chrome flagged an extension as potentially harmful
- You simply don’t recognize an extension in your list and want it gone
Why it happens: Once you’ve identified a risky extension, removal only takes a few clicks. Doing it cleanly matters for the cleanup steps that follow. Don’t rush past them.
Fix:
- On
chrome://extensions, find the extension in question. - Click Remove.
- Confirm by clicking Remove again in the popup dialog.
- Restart Chrome to make sure it doesn’t reload from a cached state.

Don’t stop here. Removing the extension doesn’t undo any account access it already grabbed. Continue to the post-removal cleanup below.
Problem: A Removed Extension Comes Back After Restarting Chrome
Symptoms:
- You remove an extension, but it reappears the next time you open Chrome
- The extension shows up again on a different device signed into the same Google Account
Why it happens: Chrome Sync reinstalls extensions across every device signed into your Google Account. Less commonly, malware on the PC itself is silently reinstalling it outside the browser.
Fix:
- Sign in to Chrome on every device you use and repeat the removal steps above on each one.
- Check Settings > You and Google > Sync and Google services to confirm sync is behaving as expected.
- Run a full scan with Windows Security (or your preferred antivirus) to rule out a system-level reinstaller.
- If it keeps returning after a scan comes back clean, treat it as a sign of deeper malware and consider resetting Chrome to default settings.
Post-Removal Cleanup
Deleting the extension only stops it from running. It doesn’t revoke any account access or undo any data it already captured. Do all three of these.
Revoke Google Account Access
- Go to myaccount.google.com/permissions.
- Review the list under Third-party apps & services.
- Click on any app or extension you don’t recognize, or one related to the extension you just removed.
- Click Remove Access.

Change Exposed Passwords
- Go to passwords.google.com.
- Run the Password Checkup to see if any saved passwords appeared in known data breaches.
- Change passwords for flagged accounts first: email, banking, and work logins matter most.
- Use unique passwords for each account going forward; Password Manager can generate them for you.

Check Active Sessions on Affected Services
- If the extension had access to accounts like Telegram, open that app’s session/device list from its own security settings. Sign out of anything unfamiliar.
- For Gmail, check Google Account > Security > Your devices for sessions you don’t recognize.
- Sign out of any session tied to a device or location you don’t know.
Error and Warning Messages Reference
| Message / Signal | What It Means | What to Do |
|---|---|---|
| “This extension may be harmful to your computer” | Chrome’s built-in safety check flagged the extension | Remove it immediately, then do the post-removal cleanup |
| “Read and change all your data on all websites” | The extension has full access to every page you visit | Fine for a password manager or ad blocker; a red flag for anything simpler |
| Extension disabled automatically by Chrome | Google removed it from the Web Store or flagged it for policy violations | Don’t re-enable it; remove it and check account access |
| “Remove” button grayed out | Extension was installed by an enterprise policy or bundled software | Check chrome://policy for ExtensionInstallForcelist, or contact IT |
| Extension reappears after removal | Chrome Sync reinstalled it, or malware is reinstalling it | Remove on every synced device and run a malware scan |
Settings to Check
- Site access per extension: Go to
chrome://extensions> Details > Site access, restrict broad access where it isn’t needed - Enterprise policies: Go to
chrome://policyto check for forced extension installs on managed devices - Chrome Sync: Go to Settings > You and Google > Sync and Google services to confirm what’s syncing across devices
- Third-party account access: Go to myaccount.google.com/permissions to remove anything unfamiliar
- Saved passwords: Go to passwords.google.com to run Password Checkup regularly
Platform-Specific Notes
On Web (Windows/Chrome OS via browser)
chrome://extensions and the account security pages work the same no matter your OS, since they’re all browser-rendered pages. The main platform-specific wrinkle is enterprise policy. On a work-managed Windows PC, IT may force-install some extensions, and you won’t be able to remove them from the extensions page. That’s expected, not a compromise.
On macOS
The steps are identical to Windows. Open Chrome, go to chrome://extensions, and use Details and Remove the same way. One difference worth knowing: macOS sometimes bundles browser helper extensions with third-party apps installed outside the Mac App Store. If an extension won’t remove cleanly, check Applications for the parent app it came with and uninstall that first.

How to Vet a New Extension Before Installing
- Search for it directly on the Chrome Web Store rather than clicking an install link from an ad or email.
- Check the developer name under Additional Information. An established company or a verified publisher badge is a good sign.
- Read the most recent reviews in addition to checking the overall star rating. Sort by newest if possible.
- Before clicking Add to Chrome, note the permissions it requests in the install prompt and confirm they match its stated purpose.
- After installing, immediately check Site access in
chrome://extensionsand restrict it to On click if you don’t need it running on every page.
Getting Help
Unexpected logins, browser settings changing on their own, or new toolbars you didn’t install are signs of malware affecting the whole system. Run a full system scan. If problems persist, consider a Chrome reset via Settings > Reset settings > Restore settings to their original defaults. Google’s own extension documentation at support.google.com/chrome/answer/2664769 covers additional management options if you’re on a managed or shared device.
Prevention Tips
- Audit extensions quarterly: Set a recurring reminder to review
chrome://extensionsevery few months and remove anything you no longer use. - Limit site access by default: Set new extensions to On click instead of On all sites unless they genuinely need constant access.
- Watch for ownership changes: Extensions you’ve trusted for years can be sold; a sudden wave of one-star reviews is often the first public sign.
- Keep Password Checkup on your calendar: Run it monthly, as a routine habit rather than only after a scare.
- Turn on two-factor authentication: Even if an extension steals a saved password, 2FA on your Google Account blocks most account takeover attempts.
Frequently Asked Questions
How do I see what permissions a Chrome extension has?
Open chrome://extensions, click Details on the extension, and scroll to the Permissions and Site access sections.
How do I know if a Chrome extension is malicious or stealing my data?
Look for broad host permissions that don’t match its stated purpose, an unfamiliar developer name on its Chrome Web Store listing, and a recent spike in one-star reviews describing odd behavior.
How do I remove a Chrome extension safely?
Go to chrome://extensions, click Remove on the extension, confirm the popup, then restart Chrome and follow the post-removal cleanup steps for your Google Account and passwords.
What should I do after removing a malicious extension?
Revoke its access at myaccount.google.com/permissions, run a Password Checkup at passwords.google.com, and change passwords for any flagged or sensitive accounts.
How do I check if an extension had access to my Google Account?
Visit myaccount.google.com/permissions and review the Third-party apps & services list; anything tied to the extension should be removed.
How can I avoid installing a malicious extension in the future?
Install only from the official Chrome Web Store, check the developer name and recent reviews before installing, and restrict new extensions to On click site access until you’re sure you need more.
Wrapping Up
Most extensions on your machine are harmless. The fix is simple: open chrome://extensions, check permissions against what each extension actually does, and remove anything that doesn’t add up. The check takes five minutes and catches almost everything. Do it now instead of waiting for the next headline to remind you.
If you do find and remove something suspicious, don’t skip the account cleanup. That’s the step people forget. It’s the one that actually protects you.
| Step | Action | Applies To |
|---|---|---|
| 1 | Review permissions and site access for every installed extension | chrome://extensions |
| 2 | Cross-check developer info and reviews for red flags | Chrome Web Store |
| 3 | Remove any suspicious extension | chrome://extensions |
| 4 | Revoke third-party account access | myaccount.google.com/permissions |
| 5 | Run Password Checkup and rotate exposed passwords | passwords.google.com |
| 6 | Vet developer and permissions before future installs | Chrome Web Store |
Last updated: 2026-08-08 | Applies to Google Chrome on Windows, macOS, and Chrome OS
