Site icon Cyber Pross

Popular Chrome Extensions Leak User Data via Unencrypted Connections

In a recent cybersecurity investigation, experts have identified several widely-used Chrome extensions that are leaking sensitive user data—including browsing history, device identifiers, and behavioral patterns—over unencrypted HTTP connections. This transmission of data without encryption leaves users dangerously exposed to interception and tampering.


🔍 Detailed Findings

Cybersecurity researchers discovered that some of the most downloaded Chrome extensions are engaging in the following:

1. Transmitting Browsing History in Plaintext

2. Unsafe VPN Practices

3. Invasive Tracking

4. Password Manager Unsafe Behavior


🧨 Hardcoded API Keys & Credentials

Some extensions also ship with hardcoded API credentials, making them vulnerable to abuse:

These static credentials can be harvested by attackers to:


⚠️ Security Risks

When data is transmitted over HTTP instead of HTTPS:


✅ What You Should Do

🔐 If You’re a User:

🛠️ If You’re a Developer:


📰 References:


⚡ Stay aware, stay secure.
Every extension you install is a potential window into your digital life. Choose wisely.

Exit mobile version