Google's Manifest V3 rules for Chrome extensions won't stop malware, but will hurt innovation, reduce capabilities, and harm performance
Context & Ripple Effects
This EFF critique lands at the end of a long tightening cycle on Chrome's extension platform. Google first cut off inline installation from third-party sites in 2018, then in 2019 moved to limit extension access to personal data and restrict Chrome's ad blocking to enterprise users (new extension and Drive API policies; enterprise-only ad blocking), with Mozilla publicly refusing to follow Google's Manifest V3 implementation because it hinders ad blockers. The 2024 disablement of Manifest V2 extensions (starting with Beta, Dev, and Canary channels) made the transition real for developers, and the EFF's assessment now frames what that transition actually bought: per the organization, the new rules won't stop malware while hurting innovation, reducing capabilities, and harming performance.
The significance is that the security rationale for Manifest V3 is being challenged by a major digital-rights group just as the old framework is being switched off — leaving developers and users with reduced capability and no demonstrated malware benefit.
First-order effects
- Extension developers shipping on Chrome must live within Manifest V3's reduced capabilities — with content blockers hit hardest, since Google already restricted current ad blocking to enterprise users despite negative feedback.
- Chrome users lose functioning extensions as Manifest V2 builds are disabled channel by channel, while the EFF's analysis says the change delivers no malware protection in exchange.
Second-order effects
- Mozilla's stated divergence from Google's Manifest V3 implementation becomes a competitive differentiator, giving Firefox a claim as the home for ad blockers and power-user extensions that Chrome can no longer run well.
- Developers maintaining cross-browser extensions must split effort between two API models or de-scope Chrome versions, raising costs across the extension ecosystem Google's own Web Store spam rules already pressure.
Third-order effects
- If the pattern holds, browser extensibility consolidates around whatever the dominant vendor's platform priorities allow — capability decisions justified as security set the ceiling for the whole add-on ecosystem, with rivals like Mozilla forced to choose between compatibility and capability.
- A repeated sequence of restriction-first policy changes (inline installs, data access, ad blocking, framework retirement) points toward regulatory or antitrust scrutiny of how much control a single browser vendor exercises over its complementary developer ecosystem.
The trend: Browser vendors are trading extension capability for platform control under a security rationale, and the gap between Google's Chrome and Mozilla's Firefox is widening into the industry's main fault line for ad blocking and user-side tools.