A browser extension once saved me enough time that I recommended it to everyone.

It cleaned up a repetitive web task, added one useful button and mostly stayed out of the way. Months later, the extension changed owners. Its privacy policy changed too. The new version wanted broader access than before.

I removed it.

The whole episode was a reminder that browser extensions are strange little pieces of software. They look smaller than normal applications because they live beside the address bar. That does not mean their access is small.

Some can read what is on the websites you visit. Some can change pages. Some can interact with downloads, tabs or browsing history. If you grant broad permission, a five-megabyte extension may know more about your working day than most software on your laptop.

And people install them after a thirty-second search.

The browser is where the valuable stuff lives

Think about what passes through a browser.

Gmail. Slack. Online banking. Customer dashboards. Cloud storage. LinkedIn. Internal company tools. Shopping accounts. Documents you opened once and forgot about.

A browser extension sits unusually close to all of this.

Obviously, permissions vary. A spelling checker does not automatically get access to your bank account. Browsers increasingly show what an extension is allowed to see and may let you restrict access to specific sites.

But the general risk is easy to underestimate because extensions feel like features rather than software.

You would probably think carefully before installing a random desktop application that asked to โ€œread and change all your data on websites you visit.โ€

Yet that wording appears during extension installation and many people click Add before finishing the sentence.

Useful extensions can become risky later

An extension may be perfectly trustworthy when you install it.

Then the developer sells it.

This is where things get uncomfortable. A popular extension with thousands or millions of users is valuable. A new owner may have different ideas about advertising, analytics or data collection. An update can change what the extension does without you reinstalling it from scratch.

I am not saying acquisitions automatically turn software malicious.

I am saying trust has a lifecycle.

We tend to make the decision once: โ€œI trust this extension.โ€ Then we keep it for five years while the code, ownership and business model change underneath us.

Software deserves occasional re-evaluation.

That sounds like work because it is.

Work browsers make the stakes higher

Personal browsing is one thing. Company systems add another layer.

A developer may have access to GitHub repositories. A salesperson may open customer records. Finance employees use payment systems. HR staff see candidate and employee information.

Now add an extension that can read page content.

This is why some companies block unapproved extensions or manage browser policies centrally. Employees sometimes find that annoying, especially when the blocked tool is genuinely useful.

I sympathise.

But browser access creates a supply-chain problem. The company is not merely trusting the employee and the website. It is trusting every extension between them.

One small tool can become a path into several otherwise well-protected systems.

โ€œRead and changeโ€ is worth reading

Browser permission messages are not written beautifully, but they matter.

If an extension needs access to one site, ask why it wants all sites. If a screenshot tool requests browsing history, that may deserve a closer look. If a note-taking extension suddenly wants new permissions after an update, do not click through purely to remove the notification.

Sometimes the explanation is reasonable. New functionality requires more access.

Sometimes you do not need the new functionality.

Many browsers let you set an extension to run only when clicked or only on chosen websites. I use that whenever practical. An extension needed for one work dashboard does not need to inspect every news site and shopping page I visit.

Least privilege sounds like enterprise security language. It works perfectly well for ordinary browser settings.

The extension store is not a guarantee

Official browser stores reduce some risk. They review software, remove known abuse and provide a central update mechanism.

Good.

They cannot guarantee every extension is safe forever.

Malicious behaviour can be hidden, introduced through compromised developer accounts or added in a later update. Reviews can also be misleading. A large number of five-star comments mainly proves that people liked the feature at some point.

Look at the developer. Check the privacy information. Notice how recently the extension was updated and whether the requested permissions match the job.

You do not need to investigate every colour-picker like a crime scene.

Use more care when the extension sits close to sensitive work.

AI extensions deserve special attention

There has been a wave of browser tools that can summarise pages, write replies, analyse documents or add AI features to websites.

Some are genuinely excellent.

They also often need to read the thing you want summarised.

If you use one on a public article, there may be little concern. If you activate it inside confidential customer notes, a private dashboard or an internal document, the information may be sent to an external AI service.

That is no longer merely a browser-extension decision. It is a data-sharing decision.

Check what is transmitted and how it is handled. If your employer has an approved AI tool, use that rather than whichever extension had the nicest screenshots.

Convenience has a talent for jumping over policy.

Remove the ones you forgot

Open your extension list.

I would bet there is something you no longer use.

Maybe a video downloader from 2022. A productivity tool you tested for a week. A theme manager. A meeting extension from a job you left.

Delete them.

Unused software still has permissions, still receives updates and still expands the number of things you must trust. There is no benefit in keeping a forgotten extension available โ€œjust in case.โ€

I clean mine every few months. The process takes less time than deciding which streaming service to cancel and is probably more useful.

The best extension is narrow and boring

I like extensions that do one obvious thing, ask for permissions that make sense and have a business model I can understand.

Boring is underrated.

The browser has become one of the most important computing environments we use. Treating everything inside it as harmless because it came from an extension store feels outdated.

That little icon beside the address bar may be incredibly helpful.

Just remember that it is software, not decoration.