Daily Guardian UAEDaily Guardian UAE
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
What's On

Google’s new desktop mode makes one thing clear: Samsung DeX was onto something

April 18, 2026

The MacBook Neo made me realize Apple still doesn’t know how to do a truly great cheap iPhone

April 18, 2026

The next Pixel phone could get a glowing back, if Android 17’s code is anything to go by

April 18, 2026

AI mode in Chrome gets a big upgrade to save you some tab hopping

April 18, 2026

NBQ Continues Resilient Performance During Q1-2026

April 18, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian UAE
Subscribe
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
Daily Guardian UAEDaily Guardian UAE
Home » Over a hundred Chrome extensions discovered raising hell. Check out if you’ve been using one
Technology

Over a hundred Chrome extensions discovered raising hell. Check out if you’ve been using one

By dailyguardian.aeApril 16, 20263 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

More than 100 Chrome extensions have been tied to a sprawling campaign that harvested identity data, opened backdoor-style browser behavior, and in one case pulled live Telegram Web session data. Researchers linked 108 add-ons to the same control network, with about 20,000 installs logged across the Chrome Web Store when the findings were published.

What makes this one hit harder is the range. The extensions showed up as Telegram tools, slot and Keno games, translation utilities, YouTube and TikTok helpers, and basic page tools, which helped the operation blend into the kind of stuff people install without much thought. See the full list here.

Researchers said the extensions were still live when the report went up, and takedown requests had already been filed. That gives this story a very practical edge for Chrome users who haven’t checked their add-ons in a while.

The worst behavior wasn’t all the same

The damage wasn’t limited to one trick. The research found that 54 extensions collected Google account identity details after a user clicked a sign-in button, while one Telegram-focused extension exfiltrated active Telegram Web session data every 15 seconds. Another 45 included a routine that could open arbitrary URLs whenever Chrome started, even if the user never opened the extension that day.

Other add-ons stripped security protections from sites like Telegram, YouTube, and TikTok before injecting overlays, ads, or scripts into pages. One translation tool also routed submitted text through the operator’s server, turning a simple helper into a surveillance risk.

Why this should worry regular Chrome users

The bigger issue is how ordinary the bait looked. These weren’t just obscure tools for power users. The list included games, browser helpers, sidebar clients, and translation add-ons, exactly the kind of extras people grab because the store page looks polished and the feature seems useful.

online privacy

Extensions also tend to fade into the background once they’re installed. In this case, researchers traced activity from that mixed bag of tools back to the same backend infrastructure, which turned a random-looking pile of add-ons into one operation with several ways to collect data or alter the browsing experience.

Check your extensions now

The smartest next move is to audit what’s installed in Chrome, especially anything tied to Telegram, lightweight games, translation, or sidebar utilities that asked for sign-in access without a clear reason. The research lists 108 extensions by name and ID, and recommends removing any match immediately.

The highest-risk case appears to be the Telegram extension that repeatedly exfiltrated web session data. Anyone who used it while logged into Telegram Web should terminate other Telegram sessions from the mobile app, and users who signed into one of the Google-linked extensions should review account access and revoke anything unfamiliar.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Google’s new desktop mode makes one thing clear: Samsung DeX was onto something

The MacBook Neo made me realize Apple still doesn’t know how to do a truly great cheap iPhone

The next Pixel phone could get a glowing back, if Android 17’s code is anything to go by

AI mode in Chrome gets a big upgrade to save you some tab hopping

Metro 2039’s eerie post-apocalyptic world looks darker, weirder, and more eldritch this Winter, and I’m already sold

Gemini now makes personalized images by understanding your taste from Photos library

AI triggered a RAMmageddon so bad that Apple looks like the sensible choice

3 underrated movies you can watch for free this weekend (April 17-19)

3 underrated Apple TV shows you should watch this weekend (April 17-19)

Editors Picks

The MacBook Neo made me realize Apple still doesn’t know how to do a truly great cheap iPhone

April 18, 2026

The next Pixel phone could get a glowing back, if Android 17’s code is anything to go by

April 18, 2026

AI mode in Chrome gets a big upgrade to save you some tab hopping

April 18, 2026

NBQ Continues Resilient Performance During Q1-2026

April 18, 2026

Subscribe to News

Get the latest UAE news and updates directly to your inbox.

Latest Posts

Metro 2039’s eerie post-apocalyptic world looks darker, weirder, and more eldritch this Winter, and I’m already sold

April 18, 2026

Gemini now makes personalized images by understanding your taste from Photos library

April 18, 2026

AI triggered a RAMmageddon so bad that Apple looks like the sensible choice

April 18, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian UAE. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.