Browser Extension Security for Small Business: The Add-Ons You Approved Once and Never Looked At Again
A trusted browser extension can turn malicious overnight. Here's why extensions are a small business blind spot in 2026, and how to see and manage them.
Someone on your team clicked "Add to Chrome" eighteen months ago. Maybe it was a PDF tool, a colour picker, a coupon finder, a screenshot helper. It worked, it was useful, and everyone forgot about it. It is still there today, still running, still watching every page they open. And here is the part almost no small business owner has thought about: the company that made it may not own it anymore.
That last sentence is not hypothetical. In late August 2026, security firm Socket published research on a campaign it calls "Superior," a cluster of 19 browser extensions for Chrome and Edge that were quietly stealing crypto wallets, login credentials, session data, and browsing history. The uncomfortable detail was how the attackers got in. Fourteen of the extensions were built by the threat actor and shipped clean, with no malware, to build up a user base. The other five were legitimate extensions with real users that the attackers simply bought, then poisoned with a malicious update.
If you run a business with a handful of staff, this is worth understanding, because browser extensions are one of the largest blind spots in small business IT. You track your laptops. You might track your software licences. Almost nobody tracks the little add-ons sitting inside the browser, which is exactly where all of your logins, your email, your banking, and your SaaS tools live.
What actually happened with the "Superior" campaign
Let's translate the news into plain English, because the technical write-ups bury the useful part.
Socket published its analysis on 27 August 2026 and disclosed the wider campaign a few days later. The attackers used a marketplace for extension ownership transfers to acquire established browser extensions that already had users and good ratings. Then they pushed an update through the official Chrome Web Store, the same trusted channel every legitimate extension uses. To the person who had the extension installed, nothing looked wrong. No warning. No new install. The add-on they approved months ago just updated itself in the background, the way extensions are designed to.
Once updated, the extensions pulled hidden code from a server controlled by the attackers, stripped out security protections on the pages people visited, and started harvesting anything valuable: wallet secrets, passwords, session cookies, and browsing history. Some of them even faked "update required" pop-ups to trick people into approving fraudulent actions.
The campaign leaned heavily on crypto theft, so it is easy to read the headline and think "that is not my business, we do not touch crypto." That is the wrong takeaway. The same technique that drains a wallet can lift the session cookie for your email, your accounting software, or your customer database. A stolen session cookie can let an attacker skip your password and your multi-factor prompt entirely, because it hands them a browser that is already logged in. It is the same trick behind the infostealer logs turning up in breach data: the attacker never needs to crack anything, because the browser already did the hard part.
Why extensions are the blind spot nobody is watching
Most small businesses have built some habits around security. You have antivirus. You have passwords. Maybe you turned on multi-factor authentication after reading one too many breach stories. Those habits cover installed software and login screens. Extensions slip through all of it.
Here is why. A browser extension is not a program you install on the computer in the normal sense, so it does not show up where you would look for installed software. Antivirus tools were not built to police what runs inside your browser. And extensions update themselves silently, which means the thing you approved is not necessarily the thing running today. You gave permission once, and that permission carries forward through every future version, including versions written by someone else.
Now stack the numbers on top of that. LayerX's Enterprise Browser Extension Security Report for 2026 found that 99% of business users have at least one extension installed, and about 25% have more than ten. More than half of users, 53%, have at least one extension with high or critical permissions, meaning it can read cookies, passwords, or the full contents of every page. And extensions do not sit still: 34% of them expanded the permissions they ask for over the past twelve months.
Read those two ideas together. Almost everyone has extensions. Most people have at least one with deep access. And a meaningful share of them are quietly asking for more power over time. That is not a niche problem. That is the normal state of a browser at a small business, and it is completely invisible unless someone goes looking. Extensions are shadow IT in its smallest, easiest-to-miss form, the same pattern as the AI tools your team signed up for without telling anyone: useful things added with good intentions, then never revisited.
"It was safe when we installed it" is the trap
The most important shift in thinking here is this: a browser extension is not a one-time decision. It is an ongoing relationship with whoever controls the code, and that owner can change.
Think about how a small extension gets built. Often it is a solo developer with a useful idea and a few thousand users. They are not running a business, they are running a side project. A few years later they lose interest, or they get an email offering real money for their little add-on, and they sell. From your side, nothing visible happens. The extension keeps working. The icon does not change. But the person deciding what code ships to your team is now a stranger, and their goals may be nothing like the original developer's.
That is precisely the mechanism the Superior campaign used. Five of the nineteen extensions were honest tools with honest histories, right up until they were not. There was no moment where an employee made a bad choice. The bad choice was made for them, quietly, by an owner they never knew existed.
This is why "we vetted it when we added it" gives false comfort. Vetting an extension at install time tells you it was fine that day. It tells you nothing about next quarter. Without some way to see what extensions your team is running and notice when things change, you are trusting a decision you made once and never revisited.
What an extension can actually see
It helps to be concrete about the risk, because "extensions can be dangerous" is easy to nod along to and ignore.
A browser extension with broad permissions can read and change the content of the web pages you visit. In practice that means it can see what you type into a form, including a password before it is submitted. It can read the page after you log in, which is where your customer records, invoices, and messages are displayed. It can access your cookies, and cookies include the session tokens that keep you logged in. If an extension can copy a live session token, it can effectively become you inside that service without ever knowing your password.
For most small businesses, the browser is the office. Your email is in the browser. Your accounting tool, your CRM, your project boards, your file storage, your payroll, your bank. An extension with full page access is standing in the middle of all of it, including every one of the SaaS tools quietly accumulating on your stack. That is a lot of trust to hand to a coupon finder nobody remembers installing.
None of this means extensions are evil or that you should rip them all out. Plenty of them are genuinely useful and perfectly safe. The point is narrower and more practical: extensions deserve the same attention you give any other tool that can touch sensitive data, and right now most small businesses give them none.
A practical playbook for small businesses
You do not need a security team to get on top of this. You need to turn an invisible thing into a visible one, then keep a light habit going. Here is a version that fits a business with one to twenty people.
Make a list of what is actually installed. In Chrome or Edge, type the extensions page into the address bar (chrome://extensions or edge://extensions) and look. Ask each person to do the same on their work machine, or handle it during a quick team catch-up. You cannot manage what you cannot see, and for most businesses this first look is genuinely eye-opening. Write down what is there.
Remove anything nobody uses or recognises. This is the fastest win. If an extension is not earning its place, it is pure risk with no upside. Coupon tools, old PDF converters, that thing someone added for one task in 2024 and never touched again. Gone. Fewer extensions means a smaller attack surface and less to keep an eye on.
Check the permissions on what stays. Each extension's page will tell you what it can access. Be suspicious of anything that can "read and change all your data on all websites" unless there is a clear reason it needs to. A note-taking clipper needing page access makes sense. A simple theme or a calculator asking for the same thing does not.
Reduce who can install extensions freely. A lot of extension risk comes from everyone being an administrator on their own machine, able to add anything at any time. Tightening this so that adding new tools involves a quick check is not about control for its own sake. It is the difference between one considered decision and a slow drip of unknowns, and it belongs in the same conversation as what you set up on someone's first day.
Put a recurring reminder in the calendar. Once a quarter, spend fifteen minutes revisiting the list. What is new? What changed? What can go? This is the step that catches the "safe when we installed it" problem, because it is the only step that looks at extensions more than once.
Keep browsers updated. Browser makers do remove malicious extensions once they are caught, and updates carry those removals plus other protections. Letting updates install is one of the highest-value, lowest-effort habits in all of small business IT, and it is the same habit that carries the rest of your Windows and application patches.
None of these steps is hard. The hard part is that today, for most small businesses, nobody owns them. There is no list, no reminder, no owner. The work is not complicated. It is just unassigned.
Where Vera fits
The reason browser extensions stay a blind spot is not that owners do not care. It is that the information lives in twenty different places, one per person per browser, and pulling it together by hand is tedious enough that it never happens. The problem is visibility, and visibility is a problem you can solve.
Vera exists to give small businesses the kind of IT overview that used to require hiring a managed IT provider. It brings your hardware, your software and licences, your team directory, and your security signals into one dashboard, so the things that normally hide in scattered corners have a single place to be seen. Instead of guessing what is out there, you get a clear picture you can actually act on, and a record you can check again later rather than rebuilding from scratch each time.
The Superior campaign is a good reminder of the pattern behind most small business IT trouble. It is rarely a dramatic hack. It is usually something ordinary that nobody was watching, quietly becoming a problem while everyone assumed it was fine. The fix is not fear. It is a habit of looking, made easy enough that it sticks.
If your browser extensions are a mystery right now, that is normal, and it is fixable. Start with the fifteen-minute list this week. If you want that visibility to be something you keep rather than a one-off spring clean, that is the gap Vera was built to close. Your IT, simplified, starts with being able to see it.