A fake or harmful Chrome extension can look official while stealing browsing or account data. That’s unnerving, but checking its source, developer, permissions, and reviews lowers your risk. You can also update your Chrome browser to ensure you have the latest security patches.
What Is Google Chrome Extensions Safety Check?
Fix #1: Understand What the Safety Check Covers
Google Chrome Extensions Safety Check is a review process. You don’t need to install another extension. You’ll use details from the Chrome Web Store, Chrome’s permission prompt, chrome://extensions, and your account security pages. For more information on Chrome extensions, you can visit the Chrome Web Store best practices page.
A harmful extension may do its stated job while reading pages or tracking you. It could also capture form entries or abuse an active login session. An extension can work correctly and still be dangerous. To learn more about Chrome extension security, you can read the Google Chrome security blog.
Prerequisites
Make sure you have:
- A Mac with the current stable version of Google Chrome
- Permission to add and remove extensions in your Chrome profile
- The Chrome Web Store listing for the extension you want to inspect
- Access to the security settings for any account that may have been exposed
- A trusted device for changing passwords after a suspected compromise
Note: A work or school administrator may manage Chrome extensions. A managed extension can show “Installed by your administrator” and may not include a Remove button. You can learn more about managing Chrome extensions in a business setting.
Step-by-Step Guide
Fix #2: Open the Extension Listing from a Trusted Source
macOS
- Open Finder.
- Select Applications in the sidebar.
- Double-click Google Chrome.

- Enter
https://chromewebstore.google.com/in Chrome’s address bar. - Press
Return. - Search for the extension by its exact name.
- Open the result, but don’t select Add to Chrome yet.
Expected result: Chrome shows a full Web Store listing instead of a download prompt from an unrelated site.
Web
- Start on the product’s official website if the company claims to offer an extension.
- Find its browser extension link.
- Confirm that it opens a page on
chromewebstore.google.com. - Check the address for misspellings, extra words, or a different domain.
- Close any page that asks you to download a file or change Chrome settings by hand.

Expected result: You reach the intended Web Store listing from a source you chose. The Web Store lowers the risk of a forced install, but a listing doesn’t guarantee safety. You can learn more about Chrome privacy extensions to help protect your data.
Fix #3: Verify the Name, Branding, and Developer
- Compare the extension’s name with the name on the product’s official website.
- Check for spelling changes, extra punctuation, or labels the company doesn’t use, such as “Official AI Assistant.”
- Treat the logo as decoration until you verify the publisher. Anyone can copy a familiar icon.
- Find the developer or publisher details on the listing.
- Open the linked website or support page in a new tab.
- Confirm that the domain belongs to the named company.
- Check whether the company’s website links to that exact extension.
- Stop if the listing uses a free email address, hides the operator, or links to an unrelated website.
Expected result: The extension name, publisher, and website point to one identity you can verify elsewhere. A polished logo proves little by itself. You can learn more about keeping your browser up to date for the best security.
Fix #4: Read the Reviews for Useful Detail
- Open the listing’s reviews section.
- Read recent positive and critical reviews.
- Look for details about a feature, Chrome version, bug, or support reply.
- Watch for repeated phrases, vague praise, matching patterns, or batches of short reviews posted together.
- Search for reports of redirects, new ads, changed search settings, broad permissions, or strange account activity.
- Compare review dates with recent extension updates when those dates are available.
- Treat the rating and install count as clues, not proof.
Expected result: You have a mix of detailed feedback. Generic or repeated reviews need a closer look, though they don’t prove harm.
One useful complaint can tell you more than 50 versions of “Works great.” Pay attention when separate reviewers report the same unwanted behavior.
Fix #5: Compare the Requested Permissions with the Extension’s Purpose
- Return to the extension listing.
- Read its description and note the exact feature you expect.
- Select Add to Chrome to open the permission confirmation dialog.
- Don’t approve the installation yet.

- Turn each permission into a plain question: “What can this extension see or change?”
- Compare that access with the advertised feature.
- Expect a page-customization extension to need access to the pages it changes.
- Ask why a calculator, theme, timer, or note tool wants access to every website.
- Select Cancel if a request seems unrelated, too broad, or too vague.
- Select Add extension only when each requested ability has a clear purpose.
Expected result: Chrome cancels the installation or confirms that it added the extension. Its icon may appear under the puzzle-piece Extensions icon.
Chrome’s permission text can sound broad because it describes types of access. “Read and change all your data on all websites” means the extension may inspect and edit pages you visit. A password manager or accessibility tool may need that access. A basic timer probably doesn’t. You can learn more about managing zip files in Chrome for better security.
Fix #6: Confirm the Installed Extension
macOS
- Select the puzzle-piece Extensions icon on Chrome’s toolbar.
- Find the extension you installed.
- Select the pin icon if you want its button to stay visible.
- Open the extension and test only the feature you planned to use.
- Remove it if it opens unrelated tabs, changes search settings, inserts ads, or requests strange sign-ins.

Expected result: The extension appears in Chrome and performs only its expected task.
A surprise sign-in page is a reason to stop testing. Don’t enter your details if the extension’s stated purpose doesn’t require an account. You can learn more about antivirus options for Chromebooks for better security.
Web
- Enter
chrome://extensionsin Chrome’s address bar. - Press
EnterorReturn. - Find the new extension card.
- Confirm that its name matches the listing you checked.
- Review its enable or disable control. Don’t change it unless needed.

Expected result: Chrome’s extensions page shows the extension among your installed items.
Configuration
Fix #7: Limit Site Access Where Chrome Allows It
- Open
chrome://extensions. - Select Details on the extension’s card.
- Find Site access.
- Check whether the extension can run On click, On specific sites, or On all sites.
- Choose On click when the extension needs short-term access.
- Choose On specific sites when it works only with known domains.
- Add only the sites needed for its main feature.
- Review the listed permissions on the same page.
- Turn off Allow in Incognito unless you have a clear reason to use it.

Expected result: The extension has only the site access its main feature needs. Chrome doesn’t offer every option for every extension.
Start with On click when it’s available. You can allow wider access later if the extension needs it. You can learn more about task management tools to help you stay organized.
Fix #8: Audit Extensions Already Installed
- Open
chrome://extensions. - Review every extension card, including disabled items.
- Find extensions you don’t use or remember installing.
- Select Details for each extension you don’t know.
- Compare its permissions and site access with its purpose.
- Select View in Chrome Web Store when available.
- Repeat the developer, website, branding, and review checks from the earlier fixes.
- Return to
chrome://extensions. - Select Remove for an extension you don’t need or trust.
- Select Remove again in the confirmation dialog.
Expected result: The suspicious or unused extension disappears and stops running in Chrome.
Be strict with forgotten extensions. Software you don’t use shouldn’t retain permission to inspect your browsing. You can learn more about software downloads for Windows 11 for better security.
Removing an extension stops its future browser activity. It can’t erase data already collected or restore changed account settings. It also can’t revoke separate OAuth access or invalidate a stolen session.
Tips and Troubleshooting
Fix #9: Resolve an Extension That Cannot Be Removed
- Check whether the extension card says it’s managed or installed by an administrator.
- Open Chrome’s menu.
- Select Settings.
- Select About Chrome, or enter
chrome://managementin the address bar. - Check whether Chrome says the browser is managed.
- Contact your administrator if this is a work or school Mac.
- Open Apple menu > System Settings > General > Device Management to check macOS configuration profiles, if that option appears.
- Don’t remove an organization’s management profile without approval.
Expected result: You learn whether an administrator controls removal instead of the extension.
I’d avoid touching a management profile on a work or school Mac. Removing it without approval can break required apps, network access, or security settings. You can learn more about fixing Windows errors for better security.
Run a trusted malware scan if a personal Mac becomes managed or a removed extension returns. Check your installed apps too. Returning extensions, forced search changes, and unknown management profiles are strong warning signs.
Fix #10: Change Passwords After Possible Credential Theft
- Stop using the affected Chrome profile for sensitive tasks.
- Move to a device you trust.
- Change the password for each account you used while the extension was installed.
- Change the password for the email account that can reset those accounts.
- Change passwords for accounts that used the same or a similar password.
- Give every account a unique password.
- Turn on two-step verification where available.
- Check recovery addresses, phone numbers, forwarding rules, and security alerts for changes you didn’t make.
Expected result: Captured passwords no longer grant account access. An attacker also can’t use your email to reset other passwords.
Start with your main email account. Next, secure your password manager, financial accounts, work accounts, and cloud storage. Finish with each service where you reused the exposed password. You can learn more about laptop battery safety for better security.
Fix #11: Revoke Connected-App and OAuth Access
- On a trusted device, open
https://myaccount.google.com/security. - Sign in to the affected Google Account if prompted.
- Find the section for connections to third-party apps and services.
- Open the full list of connections.
- Select any app or service you don’t know or use.
- Review the access it has.
- Select the option to remove or delete the connection.
- Confirm the action.
- Repeat these checks on other affected services, including Microsoft and social media accounts.

Expected result: The suspicious service no longer appears as an approved connection. Removing access may sign out the app, but it can’t delete data the app collected earlier.
OAuth access lets an app connect to your account without storing your password. A password change may leave that connection active. Check this list even after you reset your password.
Fix #12: Review Devices and Active Sessions
- Open
https://myaccount.google.com/securityon a trusted device. - Find Your devices.
- Select Manage all devices.
- Check each entry’s device type, location, browser, and last activity.
- Select a device or session you don’t know.
- Select Sign out.
- Consider signing out other sessions if someone may have stolen a session token.
- Change the account password.
- Review recent security activity for changes you didn’t make.

Expected result: Unknown sessions are signed out. Your account security page lists only devices you know.
Session hijacking lets someone use an account that’s already signed in without entering its password. Change the password and inspect active sessions after suspected data theft.
Fix #13: Respond When Suspicious Activity Continues
- Reopen
chrome://extensions. - Confirm that the extension hasn’t returned.
- Check the remaining extensions for other items you don’t know.
- Update Chrome through Chrome menu > Help > About Google Chrome.
- Restart Chrome after the update finishes.
- Check affected accounts for new sign-ins, changed recovery details, sent messages, purchases, or forwarding rules.
- Run a trusted malware scan if unwanted browser changes return.
- Contact the service’s support team or your workplace administrator if account changes or unknown sessions continue.
Expected result: Chrome is current, suspicious extensions are gone, and affected accounts show no new activity you didn’t approve.
A returning extension changes the situation. Check installed apps and management profiles because software outside Chrome may be restoring it.
Wrapping Up
Fix #5 is my pick before installation. If the requested access doesn’t match the extension’s job, select Cancel. Each permission needs a clear purpose.
If trouble continues after removal, secure your accounts from a trusted device. Change exposed passwords, remove unknown connections, and sign out strange sessions. Scan for malware if the extension returns or you find an unknown management profile.
| Step | Action | Applies To |
|---|---|---|
| Before installation | Verify the source, developer, website, branding, and reviews | macOS and web |
| Permission prompt | Compare every request with the extension’s purpose | Chrome |
| After installation | Audit chrome://extensions and limit site access | Chrome |
| Suspected theft | Change exposed passwords and secure recovery accounts | Online accounts |
| Possible OAuth abuse | Revoke unknown connected applications | Online accounts |
| Possible session hijacking | Review devices and sign out unknown sessions | Online accounts |
