TL;DR:
- Malicious browser extensions can read everything in your browser — passwords, emails, banking sessions, CRM data — without triggering any antivirus alerts.
- They’re distributed through official Chrome and Edge stores and are often disguised as productivity tools, AI assistants, or PDF converters.
- The fix is straightforward: an extension policy, a regular audit, and a few minutes of awareness training.
Ask most small business owners what they worry about in cybersecurity and you’ll hear phishing, ransomware, maybe weak passwords. Browser extensions rarely come up. But for cybercriminals, they’re one of the most reliable routes into a business — because they have legitimate access to everything in the browser, they’re trusted by the operating system, and most people install them without a second thought.
This guide explains what’s happening, what it means for your business, and how to close the gap without spending a penny.
How browser extensions steal credentials
When you install a browser extension, you grant it permissions to interact with your browser. Many extensions — PDF converters, AI assistants, ad blockers, productivity tools — need to read page content to do their job. That’s legitimate.
The problem is that “read page content” means exactly that. An extension with that permission can:
- Read the text of every page you visit, including passwords entered into login forms before they’re submitted
- Copy session cookies — the tokens that keep you logged into your online banking, cloud accounts, or accounting software
- Intercept form submissions (including when you fill in your card details)
- Read your emails as you view them
- Screenshot the current page
A malicious extension doesn’t need to break any encryption or exploit any vulnerability. It just reads what’s already on the screen. Your antivirus software won’t alert on it because the extension is doing exactly what extensions are designed to do.
How malicious extensions get onto your browser
Fake or hijacked legitimate extensions. Attackers create near-identical copies of popular extensions (a PDF converter with a slightly different name, an AI writing tool with a swapped logo) and submit them to the Chrome Web Store or Microsoft Edge Add-ons store. They stay clean for long enough to pass automated review, then push an update containing the malicious code.
Legitimate extensions that go bad. An extension developer sells their product to a buyer who then monetises it by adding data collection. The existing user base inherits the malicious version silently in a background update. This has happened multiple times with extensions that had millions of users.
Social engineering installs. Employees visit a site that pops up a prompt saying “install this extension to view this document” or “add this tool to continue.” It looks official; many people click through.
Free tools from dubious sources. Someone searches for a free screen recorder or a VPN and installs an extension from a result that looks fine at a glance.
What attackers do with stolen access
Stolen session cookies for business accounts are the most immediately valuable. With your accounting software session cookie, an attacker can access Xero, QuickBooks, or Sage — change bank details on supplier records, redirect payments, or download your entire transaction history. They don’t need your password; the session cookie means they’re already logged in.
Business email session access allows invoice fraud at scale — they can monitor payment communications and intervene at the right moment with redirected bank details.
Google Workspace and Microsoft 365 session access gives them your emails, contacts, calendars, and documents. Combined with a supplier’s email address, that’s everything needed to impersonate you convincingly.
Which employees are highest risk
Finance and accounts staff — access to banking, accounting software, and payment systems makes them the primary target.
Anyone using browser-based business tools — if your CRM, HR system, or project management runs in the browser, credentials for those systems can be harvested.
Senior staff with email access — CEO email access is valuable for business email compromise fraud.
In practice, everyone who uses a shared or business browser is exposed if an extension is installed. The risk isn’t limited to one role.
Five things you can do right now
1. Audit what extensions are installed. On any Chrome-based browser, go to chrome://extensions and look at every extension listed. Do you recognise all of them? Does each have a business reason to be there? Remove any you can’t account for.
On Edge: edge://extensions. Ask employees to do the same on their work browsers.
2. Check what permissions each extension has. Click “Details” on any extension and look at “Permissions.” Any extension with “Read and change all your data on all websites” has maximum access. That’s normal for some tools (ad blockers, password managers) but alarming for a PDF converter or an emoji keyboard.
3. Introduce a simple extension policy. You don’t need a formal IT policy document. A two-sentence rule works: “Don’t install browser extensions on work computers without checking with [owner/manager] first. If a website tells you to install an extension, don’t.”
4. Use a managed browser profile. Google Chrome and Microsoft Edge both allow administrators to restrict what extensions can be installed via policy. If you use Google Workspace or Microsoft 365, this is built into the admin console. Enable extension management and create an allowlist of approved tools.
5. Run a brief conversation with your team. Cover: what browser extensions are, that they can see everything in the browser, that you should never install one because a website asked you to, and that the rule for work computers is to ask first. Five minutes at a team meeting. That’s it.
One thing to watch for in 2026
There has been a rise in extensions impersonating AI assistants — fake versions of tools that claim to be Claude, ChatGPT, Gemini, or Copilot integrations. They often appear in search results for terms like “ChatGPT for Chrome” or “AI writing assistant.” Real AI assistants are either built into the browser (Microsoft’s Copilot in Edge) or accessed via the official website — they don’t require you to install a browser extension to use them.
If you see an employee with an AI-branded extension you don’t recognise, treat it as high priority to review.
The good news about browser extension security is that the defence is genuinely low-effort. Unlike ransomware (where the attacker has already encrypted your files before you know you’re infected), malicious extensions are removable and, if caught early, leave no persistent damage. An audit takes ten minutes. A team awareness conversation takes five. For the risk these tools represent, that’s a very good trade.