What your browser extensions can actually see
Nineteen extensions on my personal browser. I only counted them two months after cleaning out my work browser, because I had decided the work one was the serious one and stopped there.
All nineteen carried the same line in their permission list. Read and change all your data on the websites you visit.
That is the widest grant available inside a browser, and most people have handed it out a dozen times, one click at a time, usually while trying to get something else done.
What the grant actually covers
Read means the extension sees the page the way you see it. After the connection is decrypted, after the page is assembled, after your password manager has filled the login form.
So: your account balance while it is on screen. The body of an email you have open. Whatever you are typing into a form, as you type it, before you have submitted anything.
Change is the half nobody thinks about. Code holding this permission can rewrite the page in front of you. Alter what a payment page displays. Add a field that was not in the original. Repoint a link so the destination differs from the one in the status bar.
Nothing else you install sits in that position. A phone app runs in its own box and has to ask for the camera and the microphone separately, and you can refuse each one. Antivirus watches files. A VPN moves the point where your traffic joins the internet and has no visibility into the page at all.
An extension is inside the page. That is the whole job description.
The part that makes it a live problem
If an extension were frozen on the day you installed it, careful vetting would be enough. It is not frozen.
An extension with a serious install count is an asset with a market price. It updates itself, it runs on machines belonging to people who trust it, and it usually belongs to one developer who wrote it over a weekend in 2019 and has been answering support mail for free ever since.
I buy expired domains for other parts of my business. The pitch that lands in an extension developer’s inbox is the same pitch with better mechanics. A domain still has to persuade somebody to visit it. An extension is already running on every machine that ever installed it.
The update system does the rest. Extensions update silently, which is correct behaviour, because it is how a security fix reaches you the same week it is written.
No prompt appears on an update as long as the permission set is unchanged. It never needs to change, because the previous owner already asked for everything on day one.
So the version you read the reviews for is not necessarily what ran this morning. You vetted a snapshot and granted a subscription.
The store review is a filter
Both major stores review submissions, and both remove obvious junk. Worth having. It is also being asked to do two things it structurally cannot.
It reviews a version, not a future. Code that behaves for three weeks and then asks a server for instructions passes review comfortably, because during the review it does nothing wrong.
And it reviews code, while ownership is not code. Nothing in that pipeline flags that a listing changed hands in March.
Most of the extension removals that make the news started with one outside researcher noticing something odd, months after the install count went past seven figures.
How an extension tells you it changed hands
There is no notification for this. There are tells, and they are all things you have to go and look at.
The listing shows a last updated date and a publisher name. An extension that sat untouched for three years and then started shipping updates every fortnight has had something happen to it. So has one whose publisher name you do not recognise on a tool you have had since 2021.
Recent reviews are the loudest signal, because the people who liked it are the first to notice. A wall of complaints about a new account requirement, a new sidebar, or ads appearing where there were none, all dated within the same two months, is the shape of an ownership change.
An account requirement is the one I would treat as decisive on its own. A tool that worked for years without knowing who you were does not suddenly need a login for your benefit.
Open source helps here, and less than people assume. You can read the repository. What you cannot easily confirm is that the packaged build in the store was compiled from the code you just read, unless the project publishes reproducible builds, and almost none of them do.
When the request is completely fair
Do not come away frightened of the permission itself. The tools worth keeping cannot work without it.
A content blocker has to inspect every request a page makes in order to stop the ones that matter. A password manager has to read the fields to know a login form is there, and it has to check the domain it is on, which is the mechanism that stops it typing your bank password into a copy of your bank. A translator has to read the text.
So the request by itself is evidence of nothing. The gap between the request and the job is where the signal lives.
A tab manager wants all sites and needs it. A video speed controller wants all sites and needs it, because video is everywhere. A font identifier wants all sites for the ten seconds a year you use it, which is a different situation with the same permission line.
The ten minute audit
Open the extensions page from your browser menu. Then remove before you evaluate.
Anything you have not deliberately used in the last month, delete it. Not disable. A disabled extension is still installed, still holds its grant on file, and gets switched back on the first time you go hunting for something and cannot remember why it was off.
Half the list usually goes. Nobody misses any of it.
For each survivor, open its details page. Four questions:
- When did I last click this on purpose? Being vaguely useful does not count.
- Does the permission line match the job I can describe out loud?
- Who publishes it now, and when did the listing last update?
- Does it need to run always, or only when I ask?
That last question is the one with a setting attached. Site access will be sitting on all sites, and there are usually two better positions: a specific list of sites, or on click.
On click means the extension does nothing whatsoever until you click its icon. Screenshot tools, colour pickers, page archivers, the little thing that copies your open tab titles into a list. Every one of those works identically on click, and none of them are watching your bank in between.
Two extensions have a real claim to permanent access: your content blocker and your password manager. Everything else can ask.
While you are in there, turn off access in private windows unless you know why it is on. And do the profile with your money in it first.
Three beats eleven good ones
The instinct is to research each one properly, keep the ones that pass, and feel finished.
That fails on the timeline rather than on your judgement. Every extension you keep is a separate future, with its own owner, its own update schedule and its own odds of turning into something else while you are looking elsewhere. Eleven of those is eleven relationships nobody is maintaining.
Three, pinned to the sites they need, is a list short enough that you might genuinely read it again next January.
And a lot of what people install replaces a bookmark, a keyboard shortcut, or a browser feature they never went looking for.
The one I kept for seven months
A screenshot and annotation extension, installed in 2021 for support tickets, used maybe four times a year after that.
I noticed the options page had changed, and that there was now a sign-in button on something which had never needed an account. That was the moment to remove it. Instead I told myself I would look into it properly, and that took seven months.
The honest reason it stayed is that deleting it meant admitting I was never going to use it. For all seven of those months it held permission to read every page in the profile I do my banking in.
Nothing visibly bad happened, which is the uncomfortable part, because in this category you would not necessarily know. That is the argument for removing on suspicion instead of waiting for evidence.
What it cannot do
An extension is confined to the browser. It cannot read your other applications, cannot touch files on disk unless you hand them over, cannot see a browser profile it was never installed into, and cannot follow you onto your phone, where most mobile browsers still support no extensions at all.
Malware running under your user account is worse in every direction. This is the version that came in through the front door, with your permission, in exchange for a coupon.
The full audit walkthrough and the settings I actually run are here.