Browser extensions inherit powerful visibility
An extension generally sees and can alter everything on every page you visit, including your bank and your email.
That access is what makes them work, and it means trusting an extension is trusting its author now and whoever buys it later. Extensions change hands and update silently. Keeping the list short and reviewing it occasionally is the only practical control.
More on Browser security
- Same-origin policy limits which pages can read each otherSame room, different desks
- CORS relaxes browser reading rules, not authenticationA propped hatch, not a checkpoint
- SameSite cookies reduce some cross-site request risksSome journeys, not every journey
- Local storage is convenient, not a secure vaultOpen shelves by the door
- Content Security Policy constrains script sourcesOnly from the addresses you wrote down
- Clickjacking hides the real control beneath the clickPressed here. Answered there
