Google is set to start notifying users when extensions they’ve installed are removed from the Chrome Web Store.
In a Google Developers blog post on Wednesday, the company announced that Chrome users will receive a notification when an extension they’ve installed is unpublished by the developer, violates Google’s Chrome store policy, or is flagged as malware. Users will be given the option to either remove the extension or keep using it.
The new feature will be available with Chrome 117, set to be released on Sept. 12. However, Chrome 116 users can already test it.
“We have designed this change to keep the ecosystem safe for users while limiting the chances that this will impact genuine extensions,” Google explained in its blog post.
How the Chrome Web Store Addresses Violations
The Chrome Web Store’s review process ensures that extensions comply with the store’s policies.
Before they appear in the store, extensions are subject to multi-stage checks designed to ensure a high standard of security and functionality.
If a policy violation is detected during this process, the response varies based on the type of violation. Minor issues might lead to a submission being rejected, meaning the developer has to address the issues and resubmit. However, the published version of an extension will remain available unless it is found to contain malware.
Upon discovering minor policy violations in a live extension, the Chrome Web Store usually sends developers a warning, outlining the issues and providing a window of seven to 30 days for resolution. This grace period allows developers to address the issue and ensure their extensions are compliant.
However, failure to act within this timeframe might result in the extension being removed from the store. Throughout this process, the end user’s experience is preserved, as they aren’t immediately informed of these developments.
Google is not the only browser looking to protect users from potentially dangerous extensions. In July, Mozilla Firefox unveiled “Quarantined Domains,” a feature that limits unsafe extensions from operating on specific websites.
Empowering Users, Ensuring Security
Google’s new safety feature can be found under “Privacy and security” in Chrome’s settings. When an extension is highlighted, users can click “Review” to delete it or suppress the warning and continue using it.
Users curious about the new feature can test it now on Chrome 116 by navigating to “chrome://flags#safety-check-extensions” and enabling “Extensions Module in Safety Check.”
Threat actors can use extensions to access, modify, and even misuse your browser data, including passwords. Certain extensions can even alter browser settings without user consent, redirecting them to phishing pages.
In one example, in 2022, a malware-ridden Chromium browser extension dubbed “Cloud9” swiped users’ mobile browsing data and hijacked their devices.
Read our browser extensions safety guide to learn how to identify and protect yourself from potentially dangerous extensions.
