Mozilla removes four Firefox extensions made by Avast and AVG after reports that they were harvesting user data and browsing histories
The four extensions, two from Avast and two from AVG, are still available on the Chrome Web Store. — Mozilla removed today four Firefox extensions …
Context & Ripple Effects
This is the third time in three years that a major add-on store has pulled a popular extension for selling or leaking browsing histories, following the removal of Web Of Trust in 2016 and July's Nacho Analytics leak that exposed names and passwords through Chrome and Firefox extensions. The difference this time is the offender: a security vendor whose core product is trust.
Avast and AVG are not newcomers to this pattern either — [[a:862630|an AVG extension forcibly installed by its antivirus software exposed browsing history back in 2015]]. Mozilla acting unilaterally while the four extensions stay listed on the Chrome Web Store sets up a split-enforcement moment between the two biggest browser ecosystems.
First-order effects
- Avast and AVG lose their Firefox distribution channel for two extensions each, cutting off one path for the browsing-data collection Mozilla says they were harvesting.
- Chrome users keep access to all four extensions, so the same harvesting behavior remains available to them until Google acts independently.
Second-order effects
- Google faces immediate pressure to match Mozilla's removal on the Chrome Web Store, since leaving the extensions up makes Chrome the residual home for flagged data collection.
- Opera had already moved against Avast tools before the December 10 follow-up in which Avast explained it has been monetizing user browsing habits since 2013 — meaning the company's data business, not just four add-ons, is now the subject under review across multiple browsers.
Third-order effects
- If the pattern holds — Web Of Trust, Nacho Analytics, now Avast — add-on stores become the de facto privacy regulators for the extension economy, with removal decisions substituting for absent formal oversight.
- Security vendors building secondary businesses on customer telemetry face a structural credibility problem: the more their revenue depends on browsing data, the more their 'protection' products look like collection products, inviting both store-level bans and user defection.
The trend: Browser vendors are consolidating into the enforcement layer for extension privacy, repeatedly catching the security industry itself monetizing the very browsing data it promises to protect.