Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do when users need browser…
Governance, Ownership & Risk

What should organisations do when users need browser extensions but the organisation cannot fully block them?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Governance, Ownership & Risk

Use an allowlist model, require security review for new extensions, and pair it with browser and network telemetry. Focus on which extensions can access sensitive tabs, collect browsing data, or alter traffic flow. If encrypted traffic is not visible, malicious redirection and data exfiltration can be missed. Governance should also cover ownership, removal processes, and periodic reassessment of installed extensions.

How should organisations govern browser extensions without banning them outright?

When you cannot block browser extensions completely, treat them as a controlled software supply chain problem, not a convenience setting. The practical question is which extensions are allowed, what data and tabs they can reach, and how their traffic is monitored. That shifts the control point from blanket prohibition to approval, visibility, and ongoing review.

What makes browser extensions risky in a partial-allow model?

Extensions can read page content, inject scripts, alter requests, capture session data, and observe activity across tabs. That means a seemingly harmless productivity add-on can become a data collection path or a traffic manipulation path. The main failure mode is over-trust: once installed, extensions often inherit broad browser reach that users do not notice.

Security review should therefore focus on requested permissions, update behaviour, publisher trust, and whether the extension needs access to sensitive domains at all. A browser extension that can see internal apps, authentication pages, or customer data has a materially different risk profile from one that only changes the visual theme.

What operating model works best when extensions are allowed?

A strong operating model starts with an allowlist and a documented approval process for new extensions. Secrets in VS Code extensions 2025 shows why extension ecosystems deserve the same scrutiny as other software distribution channels: plugins can carry exposed credentials, broad publishing access, or supply chain risk that reaches far beyond the user interface.

Pair that with Cyberhaven Chrome extension breach 2024 as a reminder that compromise is often operational, not theoretical. Review should cover who owns each approved extension, how quickly it is removed when risk changes, and how often the installed set is reassessed against business need.

Telemetry is the other half of the model. If you cannot see browser activity and outbound traffic, you will miss redirection, data exfiltration, and hidden use of sensitive tabs. Network visibility matters especially when encrypted traffic is not inspected, because the browser can still be the point where the data leaves the environment even if the payload is opaque downstream.

Risk and Threat Considerations

Browser extensions create a high-trust execution layer inside the browser, so a weak approval model can turn normal user browsing into credential exposure, content theft, or traffic manipulation. The risk increases when extensions are widely installed, poorly inventoried, or granted access to internal applications and authentication flows.

Failure mechanism: An extension with excessive permissions or a compromised update path can observe sensitive pages, rewrite requests, or redirect traffic without being obvious to the user or standard endpoint controls.

Impact: Organisations can lose confidentiality, miss malicious redirection, and fail to detect exfiltration from browser sessions that appear legitimate at the endpoint.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack surface, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlBrowser extension approval depends on controlling access to sensitive browser sessions and tabs.
DE.CM-09 — Network MonitoringTelemetry is needed to spot extension-driven redirection and exfiltration over the network.
Recommendation — Restrict extension access to only the browser contexts and applications they must use. Monitor browser-related outbound traffic for unusual destinations and request patterns.
ISO/IEC 27001:2022A.8.9 — Configuration managementAllowlisting, ownership, and periodic reassessment are configuration controls for installed extensions.
Recommendation — Maintain an approved extension inventory and review it on a scheduled basis.
CIS Controls v8CIS-6 — Access Control ManagementExtensions should be limited to approved users, purposes, and browser contexts.
Recommendation — Apply access restrictions so only approved extensions can be installed or used.
OWASP API Security Top 10API8 — Security MisconfigurationExtensions with broad permissions or weak browser controls create misconfiguration exposure.
Recommendation — Review browser extension permissions and configuration before permitting deployment.

Practitioner Guidance

What to prioritise: Start with the extensions that can touch sensitive tabs, identity flows, customer data, or internal web apps. Those are the items where permission scope and traffic visibility have the highest security payoff.

What to verify: Confirm that every approved extension has an owner, an explicit business purpose, a removal path, and a review cadence. If any of those are missing, the extension is already operating outside a defensible control model.

Common mistake: Treating extension approval as a one-time procurement task. In practice, the risk changes when the extension updates, the publisher changes behaviour, or the business app it can reach becomes more sensitive.

Practitioner takeaway: The goal is not to eliminate browser extensions, but to make each allowed extension observable, narrowly scoped, and easy to revoke before it becomes a quiet data path.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org