tech-briefing · · 2 min read

Tech Giants Remove Popular Browser Extension After Hidden Data Collector Discovered

By Sofia Petrescu

Tech Giants Remove Popular Browser Extension After Hidden Data Collector Discovered

Hidden Feature Raises Privacy Concerns

Google and Microsoft have removed ModHeader, a widely used browser extension, from their online stores. The extension, which had about 1.6 million users on Chrome and Edge, was found to contain a concealed browsing history collector. This discovery was made by security researchers. The collector was inactive at the time of its detection.

The data collection feature remained dormant due to an empty allow-listwithin its code. This list would have specified which websites to monitor. If activated, it could have secretly gathered users' browsing data.

How Was the Collector Discovered?

The presence of this dormant collector sparked significant privacy concerns. Users were unaware of this potential data gathering capability. Browser extensions often request various permissions, but a hidden collector goes beyond typical transparency.

Security experts highlighted the danger of such features. Even if inactive, they represent a backdoor for potential misuse. The incident underscores the need for constant vigilance in browser security.

# What is ModHeader?

Researchers identified the hidden code during a routine security audit. They analyzed the extension's source code available in the official store version. This allowed them to pinpoint the data collection mechanism.

# Why was the collector dormant?

The immediate removal by Google and Microsoft shows the seriousness of the issue. Both companies acted swiftly to protect their users. This action prevents any future activation of the collector.

ModHeader is a browser extension that allows users to modify HTTP request headers. It is commonly used by developers and testers for various web development tasks.

# What are the implications for users?

The collector was dormant because its internal allow-listwas empty. This list would have specified which websites to monitor for browsing history.

Users who had ModHeader installed are now safer as the extension has been removed. The incident highlights the importance of regularly reviewing browser extension permissions and sources.

More stories:

Content written by Sofia Petrescu for techbriefe.com editorial team, AI-assisted.

Share:

Leave a comment