Google Chrome confronted with stealthy data‑collecting extensions and an active zero‑day exploit
Security researchers at Socket identified a network of 152 Chrome Web Store extensions, collectively installed over 105,000 times, that secretly gathered IP addresses, click data and browsing behavior despite declaring no data collection. The extensions, masquerading as wallpaper or gaming themes and published under 38 publisher accounts, shared information with advertising partners such as Google AdSense and DoubleClick, and some automatically generated artificial traffic to inflate ad revenue.
Separately, Google disclosed a critical zero‑day vulnerability (CVE‑2026‑11645) that is presently being exploited by attackers to gain remote control of systems running Chrome on Windows, macOS and Linux. The company urged users worldwide to apply the latest Chrome update immediately, noting that the flaw could allow full device compromise.
Both issues highlight ongoing security and privacy risks within the Chrome ecosystem, prompting calls for tighter extension vetting and prompt browser updates.