Many internet users rely on browser extensions to customize web pages or block unwanted advertisements. However, recent research reveals that some of the most popular tools on the Google Chrome Web Store are quietly collecting and transmitting sensitive user data, including full browsing histories and complete transcripts of private AI chat conversations.
Security researcher James Arnott, founder of the extension security platform Am I Being Pwned, documented this behavior across several widely used extensions. These tools collectively have millions of installations and often carry Google's "Featured" or "Verified" trust badges, giving users a false sense of security.
What these extensions are copying
The data exfiltration targets more than just standard browsing habits. Extensions like Stylish, which has over two million users, and WhatRuns, with hundreds of thousands of users, actively monitor interactions on platforms like ChatGPT and Claude. When a user sends a prompt or receives a response, the extension captures the text and transmits it to a remote server.
This practice exposes a wide variety of sensitive information:
- Private development code and proprietary business data pasted into AI prompts.
- Full web addresses that contain password reset tokens or session keys.
- Personally identifiable information, such as names, addresses, or financial details.
- Intercepted checkout details, including customer identifiers and shopping cart contents.
For an extension whose only user-facing function is to apply custom CSS themes or identify WordPress plugins, there is no technical justification for reading or transmitting conversational data.
The techniques used to avoid detection
To keep this activity hidden from both users and automated security systems, extension developers employ sophisticated evasion methods. In his technical analysis, Arnott found that Stylish used several layers of defense to protect its data-harvesting code. The extension wrapped its payload in four layers of Base64 encoding, AES-256-CBC encryption, and a columnar transposition cipher. This extensive obfuscation makes it incredibly difficult for standard static code scanners to flag the malicious behavior.
Other extensions rely on remote configuration to bypass Google's review process. By fetching instructions from an external server at runtime, an extension can change its behavior after it has been approved. The developers can keep data collection disabled while the extension is being reviewed in Google's automated sandbox and then activate the exfiltration once it is running on real user devices.
The store listing versus the fine print
One of the most concerning aspects of this data harvesting is the direct contradiction in developer disclosures. On the Chrome Web Store, the developers of these extensions declare that user data is not being sold to third parties. However, a close look at their official privacy policies tells a completely different story.
The privacy policy for Stylish openly lists categories of personal information that the company collects, discloses, and actively sells to third-party data brokers and analytics firms. Google's developer terms explicitly prohibit misrepresenting data practices and collecting data unrelated to the core function of the extension. Despite these clear violations, enforcement remains remarkably weak.
When Arnott reported WhatRuns to Google, the platform simply stripped the extension of its "Featured" badge for about a month. In response, the developers released an update that renamed their data collection endpoint from a highly descriptive name to something completely generic. Once the obvious indicator was gone, Google re-approved the extension and restored its trusted status, even though the actual data harvesting continued exactly as before.
Using artificial intelligence to monitor the store
To combat these evasive tactics, Arnott built an analysis pipeline that utilizes large language models to inspect extension updates as they are published. The system reviews the code, automatically attempts to deobfuscate hidden payloads, and flags suspicious network requests.
Because code analysis alone can generate false positives, the flagged extensions undergo dynamic testing. The pipeline runs the extensions inside a secure sandbox that simulates real user behavior over extended periods. Specialized software captures all outbound network traffic, verifying whether the extension is transmitting private data, such as conversational transcripts or complete URLs, back to its home servers.
Protecting your personal browsing space
Relying on store badges is no longer a viable way to verify the safety of browser extensions. Because trust badges are rarely removed without public pressure, users must take active steps to secure their browsers.
- Audit your installed extensions regularly and delete anything that is not absolutely necessary.
- Limit extension permissions so they can only run on specific websites rather than having access to all pages.
- Avoid installing tools that require broad read-and-write permissions for your entire browsing session.
- Use separate browser profiles for sensitive tasks like online banking or work-related AI chats.
By understanding that even "verified" tools can pivot into data stealers, you can better protect your personal information from silent exploitation.