BleepingComputer reported on August 30, 2026 that multiple Chrome and Microsoft Edge extensions delivered malware capable of stealing cryptocurrency, credentials, browser history, session data, and social media account information. The underlying Socket research identified 18 Chrome extensions and one Edge extension tied to the campaign.
The detail that matters for business owners is not only that malicious Chrome extensions were found. Socket said some extensions first appeared useful, built trust, and then became dangerous through later updates. One extension cited in the research had about 70,000 Chrome users and 10,000 Edge users at the time the malicious behavior was introduced.
The business risk is bigger than the add-on
Browser extensions sit close to daily work. Employees use the same browser for banking, payroll, Microsoft 365, Google Workspace, customer portals, social media, e-commerce, and admin tools. If an extension has broad permissions, a quiet ownership change or malicious update can turn a harmless productivity shortcut into a credential theft or session exposure problem.
That is why browser extension permissions belong in the same conversation as endpoint protection, password managers, and SaaS access. Chrome's developer documentation says extensions are designed to update automatically, and Microsoft says Edge also checks for extension updates every few hours. Auto-updates are useful for normal security fixes, but they also mean yesterday's approved add-on can become today's risk if nobody owns review.
What owners should ask their IT provider
- Do we have an inventory of installed browser extensions? Ask for a list by browser, device group, user role, and extension ID, not just a general assurance.
- Which extensions are approved for business use? Useful add-ons should have a business owner, a reason for use, and a review date.
- Are risky permissions blocked or reviewed? Extensions that can read and change data on many websites deserve extra scrutiny.
- Can Chrome and Edge extensions be controlled by policy? A managed browser policy can allow known tools, block risky ones, and prevent users from casually adding software that sees business data.
- What happens after a malicious extension report? The answer should include removal checks, password and session review, financial account precautions, and evidence that affected devices were inspected.
A practical next step
For many small businesses, the right first move is a short browser add-on review. Ask your MSP or internal IT lead for an extension inventory, the top five highest-risk permissions, and a recommendation for which add-ons should be approved, blocked, or removed. That is a manageable small business browser security project, not a months-long overhaul.
The goal is not to ban every helpful browser tool. It is to make sure convenience does not quietly outrank access control. A useful extension can still deserve a place in the business, but add-on trust should come with evidence, ownership, and a review cycle.
Sources and further reading