Site icon Cyprus inform

Browser extensions pose data security risks for Cyprus businesses

Nicosia, Cyprus. Browser extensions can access corporate data, login sessions and information entered into web pages when users grant broad permissions, creating security risks that may not be detected by traditional network defences.


Permissions and browser access

Corporate security systems have traditionally focused on firewalls and network controls. However, employees increasingly access corporate email and cloud services through browsers using single sign-on.

Browser extensions can request permissions that allow them to access websites, read page content, capture typed information and use cookies that keep users logged in. Broad host access can allow an extension to operate within a user’s authenticated browser session.

Some extensions can also collect data directly from a webpage’s Document Object Model, or DOM, including information entered into form fields, client portals and chat windows. Such activity may appear as ordinary browser traffic rather than a network intrusion.

Research findings

Security researchers examining Chrome extensions in early 2026 identified more than 300 extensions, with more than 37 million downloads combined, that were found collecting browsing histories and personal data.

In June, Microsoft said it had dismantled a campaign named StegoAd involving 119 extensions used by up to 2.6 million people. The extensions presented themselves as tools including ad blockers, calculators and PDF utilities.

Microsoft said malicious code was concealed in extension icon images and activated after a delay. Once active, it collected login credentials and session cookies, enabling account hijacking without requiring a password.

Researchers at the University of Surrey analysed 21,000 Chrome extensions and found that about one in six began third-party tracking within 60 seconds of installation. The extensions were collectively used by more than 600 million people, according to the researchers.

Governance measures

Policies prohibiting unapproved extensions may not prevent employees from installing tools needed for immediate tasks such as translation, document conversion or other workplace functions.

Browser-level technical governance can provide visibility over where sensitive data is accessed, entered or transferred in browser tabs. Zero-trust workflow mapping can help organisations identify data flows from secure systems to browser-based services and apply controls at those points.

Cyprus is seeking to strengthen its position as a base for international business and technology firms. Extending data governance to browser activity is part of protecting client information and addressing browser-based security risks.

Exit mobile version