Google says 5% of its visitors have ad injectors installed, disables 192 deceptive Chrome extensions
Frederic Lardinois / TechCrunch :
Context & Ripple Effects
This is Google's first public accounting of ad injection inside its own browser: 5% of visitors to its sites had an ad injector installed, so Google disabled 192 deceptive Chrome extensions. A month later, Google's own study put the figure at 5.5% of unique visitors, tying the practice to more than 3,000 affected advertisers.
The cleanup did not end there. Over the following years Google kept pulling malicious extensions at scale — including five posing as ad blockers with browser-hijacking scripts in 2018 and a network of 500+ fraudulent extensions removed in 2020 — while researchers separately surfaced a cluster of 295 extensions with over 80M users inserting ads into search results. This 2015 action is the template for what became a recurring enforcement cycle.
First-order effects
- Users who installed any of the 192 extensions lose the functionality they downloaded, and the developers behind them are cut off from distribution via the Chrome Web Store.
- Advertisers whose ads were being replaced or overlaid by injectors get a cleaner channel to Google visitors, since roughly one in twenty was previously exposed to injected ads.
Second-order effects
- Legitimate extension developers face tighter review and policing of the Web Store as Google distinguishes honest add-ons from deceptive ones, raising the compliance bar for distribution.
- Ad-injection operators shift tactics — the later fake ad-blocker and large-scale fraud-network removals show the same abuse re-emerging under new disguises after each purge.
Third-order effects
- If the pattern holds, extension-marketplace security becomes a permanent operating cost for browser vendors rather than a one-off cleanup, pushing platforms toward continuous scanning, permission restrictions, and transparency tooling like Google's later ad-load disclosure extension.
- Advertisers gain leverage to demand verified, injection-free delivery, making measurement integrity across the open web a structural differentiator between closed and extensible browsers.
The trend: Browser-extension abuse is a recurring cat-and-mouse problem, with Google's purge-then-measure cycle becoming a standing feature of Chrome Web Store governance rather than a single event.