Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better

    August 8, 2025

    21 Best Festival Accessories and Gear (2025): The Essentials and the Fun Stuff

    August 8, 2025

    Panasonic ShinobiPro MiniLED TVs Launched in India Alongside New 2025 P-Series Models

    August 8, 2025
    Facebook X (Twitter) Instagram
    Trending
    • I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better
    • 21 Best Festival Accessories and Gear (2025): The Essentials and the Fun Stuff
    • Panasonic ShinobiPro MiniLED TVs Launched in India Alongside New 2025 P-Series Models
    • Ready or Not Regains Flagship Xbox Feature, Play Anywhere
    • Here’s how I stop spam emails from ever reaching my inbox
    • Breath Work, Biohacking, and Cryotherapy: New Buzzwords for Modern Business Travelers
    • Apple Must Allow Alternative Browser Engines on iOS by December Under Japan’s New Mobile Software Competition Act
    • Samsung Galaxy Buds 3 Series Update Adds Google Gemini Support on Phones Running One UI 8
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»AI & Tech»Your browser’s tools can’t see what extensions are really doing – and hackers know it perfectly well
    AI & Tech

    Your browser’s tools can’t see what extensions are really doing – and hackers know it perfectly well

    techupdateadminBy techupdateadminAugust 2, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Representational image of a hacker
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • Labels like “Verified” give a false sense of safety but don’t reflect real extension behavior
    • Browser DevTools were never meant to track how extensions behave across tabs and over time
    • Malicious extensions often act normally until specific triggers make their hidden features come alive

    The unchecked spread of malicious browser extensions continues to expose users to spyware and other threats, largely due to deep-seated flaws in how the software handles extension security.

    New research from SquareX claims many people still rely on superficial trust markers like “Verified” or “Chrome Featured,” which have repeatedly failed to prevent widespread compromise.

    These markers, while intended to reassure users, often offer little insight into the actual behavior of an extension.


    You may like

    Labels offer little protection against dynamic threats

    A central issue lies in the limitations of Browser DevTools, which were designed in the late 2000s for web page debugging.

    These tools were never meant to inspect the far more complex behavior of modern browser extensions, which can run scripts, take screenshots, and operate across tabs, actions that existing DevTools struggle to trace or attribute.

    This creates an environment where malicious behaviors can remain hidden, even as they collect data or manipulate web content.

    The failure of these DevTools lies in their inability to provide telemetry that isolates extension behavior from standard web activity.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    For instance, when a script is injected into a web page by an extension, DevTools lack the means to distinguish it from the page’s native functions.

    The Geco Colorpick incident offers an example of how trust indicators can fail catastrophically – according to findings from Koi Research, 18 malicious extensions were able to distribute spyware to 2.3 million users, despite carrying the highly visible “Verified” label.

    To address this, SquareX has proposed a new framework involving a modified browser and what it calls Browser AI Agents.

    This combination is designed to simulate varied user behaviors and conditions, drawing out hidden or delayed responses from extensions.

    The approach is part of what SquareX terms the Extension Monitoring Sandbox, a setup that enables dynamic analysis based on real-time activity rather than just static code inspection.

    At the moment, many organizations continue to rely on free antivirus tools or built-in browser protections that cannot keep up with the evolving threat landscape.

    The gap between perceived and actual security leaves both individuals and companies vulnerable.

    The long-term impact of this initiative remains to be seen, but it reflects a growing recognition that browser-based threats demand more than superficial safeguards.

    You might also like

    browsers extensions Hackers perfectly Tools
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleToday’s NYT Strands Hints, Answer and Help for Aug. 2 #517
    Next Article Decoding Mark Zuckerberg’s ‘personal superintelligence” plan for Meta
    techupdateadmin
    • Website

    Related Posts

    AI & Tech

    I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better

    August 8, 2025
    AI & Tech

    Apple Must Allow Alternative Browser Engines on iOS by December Under Japan’s New Mobile Software Competition Act

    August 8, 2025
    AI & Tech

    Why VPNs Matter in Today’s UK Digital Landscape

    August 8, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Apple Pencil With ‘Trackball’ Tip, Ability to Draw on Any Surface Described in Patent Document

    July 9, 20253 Views

    Samsung Galaxy Z Fold 7 and Galaxy Z Flip 7: First Impressions

    July 9, 20253 Views

    The Bezos-funded climate satellite is lost in space

    July 9, 20252 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    I Didn’t Know This 5-Minute Bedtime Task Would Help Me Sleep Better

    August 8, 2025

    21 Best Festival Accessories and Gear (2025): The Essentials and the Fun Stuff

    August 8, 2025

    Panasonic ShinobiPro MiniLED TVs Launched in India Alongside New 2025 P-Series Models

    August 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2025 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.