Duo Security survey of 120K+ Chrome extensions finds 35.4% ask users for permission to access and read all their data on any site, 84.7% had no privacy policy
Eighty-five percent of all Chrome extensions don't have a privacy policy. — More than a third of all Google Chrome extensions ask users …
Context & Ripple Effects
Duo Security's audit put numbers on a problem the ecosystem had only treated anecdotally: of 120K+ Chrome extensions, more than a third request read access to user data on every site, and nearly 85% publish no privacy policy at all. The finding landed months before Google's tightening of extension and Drive API data policies, which reads in hindsight as a direct response to exactly this kind of permission sprawl.
The survey also foreshadowed what unchecked permissions enable in practice: within months, extensions with up to 4M installs were caught leaking names and passwords to Nacho Analytics, and by mid-2020 Google had removed 106 malicious extensions with 32M downloads after researcher discovery. A companion analysis of the store itself showed why enforcement is hard — most of 188,620 extensions sit below 16 installs, so risk hides in a very long tail.
First-order effects
- Chrome users granting 'read all data on any site' permissions are exposed immediately: any installed extension among the 35.4% can capture browsing activity site-wide, with no privacy policy telling them how it will be used.
- Extension developers without privacy policies now face a compliance gap against Google's announced summer policy changes, which limit third-party access to personal data.
Second-order effects
- Google is pushed from passive store hosting toward active gatekeeping — the Nacho Analytics leak and the 2020 removal of 106 malicious extensions show the platform absorbing review and takedown costs that the open submission model externalized.
- Legitimate developers absorb the cost of stricter vetting and documentation requirements, while the long tail of near-zero-install extensions makes targeted auditing economically difficult for Google.
Third-order effects
- If the pattern holds, browser extension ecosystems consolidate around platforms that enforce permission boundaries and privacy-policy requirements as a condition of distribution, trading openness for audited trust.
- The repeated cycle of survey, leak, and mass takedown points toward browsers treating extension data access as a first-class security surface — with default-deny permission models becoming the norm rather than opt-in hygiene.
The trend: Browser extension ecosystems are shifting from open, self-policed distribution toward platform-enforced permission and privacy controls, driven by recurring abuse at scale.