Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What happens when malicious browser extensions or add-ons…
Cyber Security

What happens when malicious browser extensions or add-ons are installed without strong governance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Cyber Security

Unchecked extensions can expand the attack surface far beyond the browser itself. They may inject scripts, harvest data, redirect traffic, or act as a delivery mechanism for malware and credential theft. Even when a store removes a malicious extension, it may remain installed on user devices, so organisations need policy enforcement, review, and removal processes to reduce residual exposure.

How Malicious Browser Extensions Change the Browser Security Model

Browser extensions are not just add-ons, they become part of the browser’s trusted execution environment. Once installed, they can read and modify pages, observe session activity, and interact with sites on behalf of the user. That means a weakly governed extension can convert a normal browser into a platform for script injection, traffic manipulation, data harvesting, and account abuse.

The practical risk is not limited to obviously malicious code. A legitimate extension can be sold, compromised, or updated into a harmful state, which is why organisations should treat extension approval as a security control rather than a convenience choice. For a useful comparison of how extension compromise can become a supply-chain event, see Cyberhaven Chrome extension breach 2024.

Why Residual Exposure Persists After Removal

Even when a browser store takes down a harmful extension, the installed copy can remain active on endpoints until it is explicitly removed. That creates a persistence problem: the distribution channel may be closed, but the local runtime exposure still exists. In practice, this means the organisation must manage extension inventory, version state, and device-level removal, not just rely on marketplace takedowns.

Residual exposure becomes worse when the extension had already captured tokens, cookies, or page content before detection. An extension can be a short-lived foothold with long-lived consequences, especially if it was allowed broad site access or installed by a user without review. That is why the issue is best understood as both a browser control problem and a credential exposure problem, not just a software hygiene problem. A concrete example of extension-based token theft and update abuse is GlassWorm campaign 2025.

What Strong Governance Actually Needs to Cover

Strong governance means deciding which extensions are permitted, how they are reviewed, how they are distributed, and how they are removed when risk changes. The control gap usually appears when organisations have no inventory, no owner, and no enforcement path, so users can install tools faster than security teams can assess them. The result is inconsistent trust decisions across departments and devices.

  • Approve only the minimum set of extensions needed for a role or workflow.
  • Review requested permissions, not just the extension name or publisher.
  • Block unmanaged installation paths where policy can be enforced centrally.
  • Reconcile installed extensions against an approved inventory on a recurring basis.
  • Remove extensions promptly when they are deprecated, compromised, or no longer justified.

Where governance is weak, malicious extensions can also become an entry point for broader compromise, including token abuse and secondary malicious updates. An internal supply-chain case that illustrates this pattern is Secrets in VS Code extensions 2025.

Risk and Threat Considerations

Browser extensions are attractive to attackers because they sit close to authenticated user sessions, sensitive web content, and normal browsing trust. A malicious or compromised add-on can silently observe pages, alter transactions, or exfiltrate data while appearing to be ordinary browser functionality. The main operational risk is that the browser becomes a privilege amplifier rather than a controlled access layer.

Failure mechanism: The extension gains excessive permissions, survives marketplace removal on already-infected devices, or is updated after trust has already been granted, allowing script injection, session abuse, data theft, or malware delivery.

Impact: Organisations can lose confidentiality, integrity, and account control at browser scale, with exposure extending to credentials, customer data, internal web apps, and downstream cloud or SaaS sessions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementControls approved software and user-installed extensions on endpoints.
Recommendation — Restrict extension installation to approved software and remove unapproved browser add-ons.
NIST SP 800-53 Rev 5CM-7 — Least FunctionalityLimits installed browser add-ons to the minimum needed for business use.
SI-7 — Software, Firmware, and Information IntegrityDetects tampering, malicious updates, and integrity loss in trusted browser code.
Recommendation — Allow only required extensions and block unnecessary browser functionality. Verify extension integrity and monitor for unauthorized code changes or updates.
ISO/IEC 27001:2022A.8.19 — Installation of software on operational systemsDirectly governs controlled installation of browser extensions on user systems.
Recommendation — Approve and restrict browser extension installation on operational systems.
NIST CSF 2.0PR.AA-05 — Least privilege is established and managed for users, systems, and devicesBrowser extensions need tightly scoped permissions and ongoing privilege management.
Recommendation — Limit extension permissions and review them against least-privilege requirements.

Practitioner Guidance

What to prioritise: Start with the browsers and user groups that reach the most sensitive web applications, then work backward to the extension list they are allowed to run. High-value users, support teams, developers, and finance staff often deserve the tightest approval model because extension misuse there has the widest blast radius.

What to verify: Confirm that your environment can identify every installed extension, distinguish approved from unapproved add-ons, and remove blocked items rather than only warning about them. If you cannot produce an authoritative installed-extension inventory, you do not yet have meaningful governance.

Common mistake: Treating marketplace vetting as sufficient. A store review reduces some risk, but it does not replace endpoint enforcement, user permission review, or post-install monitoring for updates, permission changes, and suspicious behaviour.

Practitioner takeaway: The control objective is not to ban all extensions, it is to make every allowed extension accountable, minimal, and removable before it can turn browser trust into persistent exposure.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org