Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Delisted Extension
Cyber Security

Delisted Extension

← Back to Glossary
By NHI Mgmt Group Updated September 6, 2026 Domain: Cyber Security

A delisted extension is one that no longer remains available in a marketplace but is still installed on endpoints. That state matters because removal from the store does not automatically remove existing copies, so the extension may continue to run and expose users until it is explicitly remediated.

Expanded Definition

A delisted extension is a browser, application, or platform extension that has been removed from an official marketplace or store but still exists on one or more endpoints. The important boundary is that delisting changes distribution status, not local presence: if the extension was already installed, it may continue to load, retain permissions, and interact with data until administrators or users remove it.

That distinction is easy to miss because many teams assume store removal equals neutralisation. It does not. Delisting usually indicates a policy, security, support, or compliance decision by the platform owner, but the installed copy can remain operational unless there is a separate enforcement mechanism on the device. For security teams, the term sits closer to software inventory and endpoint governance than to simple catalog management.

A common misunderstanding is treating delisting as a cleanup event. In practice, it is often an intelligence signal that requires endpoint discovery, version review, and ownership checks. For platform governance and software trust decisions, the relevant question is not whether the listing disappeared, but whether the extension is still active anywhere it should not be.

Examples and Use Cases

Delisted extensions appear in ordinary enterprise environments in several ways:

  • A browser extension is removed from a public store after review concerns, but employees who installed it earlier still have it running.
  • An internal productivity extension is delisted during migration to a new version, while unmanaged endpoints keep the old copy in place.
  • A security team identifies an extension that is no longer supported by its publisher, then checks whether it still has access to sensitive pages or session data.
  • An organisation uses endpoint management to compare installed extensions against an approved list and flags delisted items for removal.
  • A platform operator delists an extension due to policy violations, and IT must decide whether to block, quarantine, or replace it.

The operational tradeoff is straightforward: store visibility is useful for discovery, but it is not a reliable control plane for removal. If endpoints are not centrally managed, delisted extensions can persist indefinitely, especially on personal or exception-based devices.

For governance teams, this often becomes a reconciliation exercise between marketplace status, installed inventory, and business ownership. The extension may be unavailable to new users, yet remain a live dependency for existing ones.

Security Implications

Delisted extensions create residual exposure because the security event is often only half complete. Even after removal from the marketplace, the installed extension may still hold broad browser permissions, access page content, or interact with authentication flows. If the extension is unsafe, unsupported, or malicious, those permissions can continue to create data leakage, session abuse, or supply-chain risk on already-infected endpoints.

The failure mode is usually inventory blindness. Security teams may assume a delisting action has reduced exposure, while the actual attack surface remains until the extension is explicitly removed or disabled. That gap can leave organisations with unmonitored code running inside the browser, which is especially problematic when extensions can read content, modify pages, or observe user activity.

In practice, the observable symptoms are uneven: some endpoints lose the extension quickly, while others keep it for weeks or months. That makes endpoint scoping, ownership assignment, and remediation tracking critical. The security question is not just whether the extension is bad, but whether any managed or unmanaged device still trusts it.

Domain and Governance Relevance

In identity and access environments, a delisted extension matters because browser extensions often sit close to login flows, tokens, and user sessions. That proximity means a legacy or unsupported extension can affect credential handling, page instrumentation, or access to identity portals even when it is no longer available for fresh installs.

From a governance perspective, delisting should trigger a lifecycle decision: remove, replace, restrict, or formally approve an exception. The term is therefore relevant to software asset management, endpoint control, and trust governance, not merely to marketplace hygiene. Where extensions support SSO, password management, session helpers, or workflow automation, the governance bar is higher because the extension can influence identity-bearing activity.

For NHIMG, the practical interpretation is that delisting is only meaningful when paired with endpoint visibility and explicit offboarding. A removed listing without removal on devices leaves a live software identity in circulation, which can outlast the platform decision that created the delisting.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v82.1 — Inventory and Control of Enterprise AssetsDelisted extensions remain installed assets that need discovery and tracking.
2.3 — Address Unauthorized AssetsDelisted copies can persist as unauthorized software after store removal.
4.1 — Establish and Maintain a Secure Configuration ProcessExtension delisting should feed configuration enforcement on browsers and endpoints.
Recommendation — Inventory installed extensions and remove delisted items from managed endpoints. Detect and quarantine delisted extensions that persist outside approved software. Enforce browser configuration baselines that block unapproved extensions.
NIST CSF 2.0ID.AM-1 — Physical Devices and Systems InventoriedInstalled extensions must be visible in asset inventories to spot delisted copies.
PR.AC-4 — Access Permissions and Authorizations ManagedDelisted extensions may still retain permissions after marketplace removal.
PR.IP-1 — Configuration Management Policy and ProcessesDelisting requires a controlled process for removal and exception handling.
Recommendation — Map extension inventory into endpoint asset records and reconcile delisted entries. Revoke extension permissions when an extension is delisted or unsupported. Apply configuration management to remove or disable delisted extensions consistently.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 6, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org