Back to Blog

How to Tell if a Chrome Extension Is Spying on You

PB

Patrick Bushe

April 13, 2026 · 5 min read

Most extensions are harmless, but every one you install can see the pages it has access to. Some collect browsing data to sell, and good extensions sometimes turn bad after being sold or hacked. Here's how to spot one that's spying, and check.

Warning signs

  • Permissions that don't fit. A calculator or wallpaper extension asking to "read and change all your data on all websites" or your browsing history.
  • New permissions after an update. Chrome disables the extension until you approve. Don't approve without a reason.
  • A new owner. Popular extensions are sometimes bought and then updated to collect data or inject ads. A changed developer name or website on the Web Store listing is a red flag.
  • Changed search engine or new tab page, pop-ups, extra ads on sites that didn't have them, or links redirecting through strange addresses.
  • Reviews that suddenly mention spam, ads or redirects.

See where an extension sends data

  1. Go to chrome://extensions and turn on Developer mode.
  2. Under the extension, click the service worker (or background page) link next to "Inspect views".
  3. Open the Network tab and use Chrome normally for a while.

Requests to the developer's own server for updates or settings are normal. Requests to analytics or data companies on every page you visit are not. Content scripts that run inside pages show their requests in that page's own DevTools Network tab.

Read what the developer has declared

On the Chrome Web Store listing, scroll to Privacy practices. Developers must state what data they collect and whether they sell it. A missing or vague privacy policy is a bad sign. Some people also check an extension's code with a CRX viewer extension, which shows the files inside.

Real incidents

This isn't theoretical. In December 2024, attackers phished the developers of several popular extensions, including the security company Cyberhaven, and pushed malicious updates that stole session data. The extensions had been trustworthy until that update, which is why watching for unexpected changes matters.

What to do if you suspect one

  1. Remove it at chrome://extensions.
  2. Run Safety Check in Chrome's settings.
  3. Change passwords for important accounts, and sign out of other sessions, especially if the extension could read all sites.
  4. Report it from its Web Store page using Report abuse.

Keep the risk low

  • Install fewer extensions, and remove ones you don't use.
  • Set site access to On click or specific sites where possible.
  • Prefer extensions with a named developer, a website and a clear privacy policy.

For more, see what extension permissions mean and how to test an extension before trusting it.

More Tools by Patrick Bushe

Free Chrome extensions to boost your productivity and privacy