/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Duo Security survey of 120K+ Chrome extensions finds 35.4% ask users for permission to access and read all their data on any site, 84.7% had no privacy policy

Eighty-five percent of all Chrome extensions don't have a privacy policy.  —  More than a third of all Google Chrome extensions ask users …

ZDNet Catalin Cimpanu

Context & Ripple Effects

Duo Security's audit put numbers on a problem the ecosystem had only treated anecdotally: of 120K+ Chrome extensions, more than a third request read access to user data on every site, and nearly 85% publish no privacy policy at all. The finding landed months before Google's tightening of extension and Drive API data policies, which reads in hindsight as a direct response to exactly this kind of permission sprawl.

The survey also foreshadowed what unchecked permissions enable in practice: within months, extensions with up to 4M installs were caught leaking names and passwords to Nacho Analytics, and by mid-2020 Google had removed 106 malicious extensions with 32M downloads after researcher discovery. A companion analysis of the store itself showed why enforcement is hard — most of 188,620 extensions sit below 16 installs, so risk hides in a very long tail.

First-order effects

  • Chrome users granting 'read all data on any site' permissions are exposed immediately: any installed extension among the 35.4% can capture browsing activity site-wide, with no privacy policy telling them how it will be used.
  • Extension developers without privacy policies now face a compliance gap against Google's announced summer policy changes, which limit third-party access to personal data.

Second-order effects

  • Google is pushed from passive store hosting toward active gatekeeping — the Nacho Analytics leak and the 2020 removal of 106 malicious extensions show the platform absorbing review and takedown costs that the open submission model externalized.
  • Legitimate developers absorb the cost of stricter vetting and documentation requirements, while the long tail of near-zero-install extensions makes targeted auditing economically difficult for Google.

Third-order effects

  • If the pattern holds, browser extension ecosystems consolidate around platforms that enforce permission boundaries and privacy-policy requirements as a condition of distribution, trading openness for audited trust.
  • The repeated cycle of survey, leak, and mass takedown points toward browsers treating extension data access as a first-class security surface — with default-deny permission models becoming the norm rather than opt-in hygiene.

The trend: Browser extension ecosystems are shifting from open, self-policed distribution toward platform-enforced permission and privacy controls, driven by recurring abuse at scale.