Close Menu
Hywhos – Health, Nutrition & Wellness Blog
    What's Hot

    Your Browser’s Extensions May Be Reading Your Passwords

    February 10, 2026

    I Asked 4 Chefs for the Best Store-Bought Pizza Sauce, and Their Favorite Is Ours, Too

    February 10, 2026

    7-Day Anti-Inflammatory Meal Plan for Lower Dementia Risk

    February 10, 2026
    Facebook X (Twitter) Instagram
    • Home
    • Shop
      • Fitness
    • Fitness
    • Recipes
    • Wellness
    • Nutrition
    • Diet Plans
    • Tips & Tricks
    • More
      • Supplements
      • Healthy Habits
    Facebook X (Twitter) Instagram Pinterest
    Hywhos – Health, Nutrition & Wellness Blog
    Tuesday, February 10
    Hywhos – Health, Nutrition & Wellness Blog
    Home»Tips & Tricks»Your Browser’s Extensions May Be Reading Your Passwords
    Tips & Tricks

    Your Browser’s Extensions May Be Reading Your Passwords

    8okaybaby@gmail.comBy 8okaybaby@gmail.comFebruary 10, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Your Browser’s Extensions May Be Reading Your Passwords
    Share
    Facebook Twitter LinkedIn Pinterest Email

    We should all take common-sense steps to make sure our data stays safe and secure: use strong passwords with our accounts, and never reuse passwords; employ two-factor authentication on any account that offers it; and avoid clicking strange links in emails or text messages. But even when you follow all those rules, your personal data can still be at risk, strictly because the services you rely on aren’t following these rules themselves.

    Some websites are putting your passwords at risk

    Researchers at the University of Wisconsin-Madison discovered that a concerning number of browser extensions can access sensitive information that you enter into websites. Think passwords, credit card info, and Social Security numbers.

    The team behind the discovery says they weren’t out looking to break a security story. Instead, they were “messing around with login pages,” specifically Google login pages, when they found that the sites’ HTML source code could see the passwords they entered in plain text. They turned their sights onto other websites—more than 7,000, reportedly—and found that about 15% of them were also storing sensitive information in plain text. That’s over 1,000 websites exposing important data.

    That, of course, is not supposed to happen: When you enter sensitive data into a website—say, your password into Google’s login page—that site shouldn’t see your password at all. In short, the sites confirm your passwords through hashing algorithms—essentially, jumbling your password into a code that can be checked against the code the site stores on their end. They can then confirm you entered the right password without ever exposing the actual text. By storing things like passwords and Social Security numbers in plain text, those sites are exposing that data to anyone in the know.

    Importantly, that includes browser extensions. The researchers claim that 17,300 Chrome extensions—or 12.5% of the extensions available for download on Google’s browser—have the permissions they need to view this sensitive plain text data. Think about the permissions you ignore when setting up a new extension, including permissions that give extensions full access to see and change what you enter on a webpage. Researchers didn’t expose any extensions by name, as the situation is not necessarily the fault of the extensions, but considering the scope, it’s possible some of the extensions you use can access sensitive information you enter in certain sites.

    Again, legitimate extensions are not the priority: Instead, it’s the risk that a developer will create an extension with the intent of scraping sensitive info stored in plain text. While the researchers claim there are no extensions actively abusing this vulnerability yet, this isn’t a theoretical problem. Researchers created an extension from scratch that could pull this user data, uploaded it to the Chrome Web Store, and got it approved. They took it down immediately, but proved it’s possible for a hacker to get such a malicious extension on the official store. Even if the hacker didn’t make the extension, they could acquire a legitimate extension with an existing user base, adjust the code to take advantage of the vulnerability, and spring the updated extension on unsuspecting users. It happens all the time, and not just on Chrome.


    What do you think so far?

    How to protect your sensitive data from malicious browser extensions

    Unfortunately, there’s little you can do to prevent these sites from storing your passwords, credit cards, and Social Security numbers in plain text. The hope is, following these discoveries, websites will improve their security and kill the vulnerabilities on their end. But that’s on them, not you.

    There are some steps you can take to mitigate the damage, however. First, make sure to limit your use of browser extensions. The fewer extensions you use, the less likely it is you’ll use a malicious one. Use only extensions you fully trust, and frequently check in on updates. If the extension changes hands to a new developer, vet that new owner before continuing to use it. You could even disable your extensions when sharing sensitive information with websites. If you need to provide your Social Security number on an official web form, for example, you could disable your extensions to prevent them from reading the data.

    You can also limit the data you share that could stored in plain text. If given the option, use passkeys instead of passwords, as passkeys don’t actually use any plain text data that hackers could steal. Similarly, use secure payment systems, such as Apple Pay or Google Pay, which don’t actually share your credit card information with the website you’re making a payment on. The name of the game is to avoiding typing out your sensitive details unless absolutely necessary—and then, reducing the parties who can see those details.

    Browsers Extensions Passwords Reading
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    8okaybaby@gmail.com
    • Website

    Related Posts

    The Best Canned Foods to Eat on the Mediterranean Diet, According to a Dietitian

    February 10, 2026

    This Popular AI Chat App Exposed 300 Million Private Messages

    February 10, 2026

    6 Foods with More Vitamin D Than an Egg

    February 10, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Best microwaves to buy 2025, tested and reviewed

    October 8, 202529 Views

    13 best kitchen scales 2025, tested and reviewed

    October 1, 202525 Views

    Best cake tins to buy in 2025, tested and reviewed

    October 8, 202523 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    About

    Welcome to Hywhos.com – your go-to destination for health, nutrition, and wellness tips! Our goal is to make healthy living simple, enjoyable, and accessible for everyone.

    Latest post

    Your Browser’s Extensions May Be Reading Your Passwords

    February 10, 2026

    I Asked 4 Chefs for the Best Store-Bought Pizza Sauce, and Their Favorite Is Ours, Too

    February 10, 2026

    7-Day Anti-Inflammatory Meal Plan for Lower Dementia Risk

    February 10, 2026
    Recent Posts
    • Your Browser’s Extensions May Be Reading Your Passwords
    • I Asked 4 Chefs for the Best Store-Bought Pizza Sauce, and Their Favorite Is Ours, Too
    • 7-Day Anti-Inflammatory Meal Plan for Lower Dementia Risk
    • The 20 Best Amazon Outlet Deals Ahead of Presidents Day Weekend
    • Can Antibiotics Affect Fertility? Insights and Impacts Explained
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 hywhos. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.