Let's Talk About the Browser Extensions You Forgot You Installed...

·4 min read

A quick experiment

Open your browser’s extensions page right now (in Chrome it’s under Settings, in Firefox it’s Add-ons). Take a look at the list. If you’re anything like us, there’s at least one extension in there you installed for a single task two years ago and never touched again. A PDF converter. A grammar checker. Something that promised to find you coupon codes back when you were in your finance-maxing era.

Most of them are harmless. Some of them can see every page you visit, including the ones where you type in a client’s card number or log into your work portal.

What “access to all websites” really means

When you install a browser extension, it asks for permissions. A lot of extensions, even simple-looking ones, ask for something like “read and change all your data on the websites you visit.” That permission isn’t unusual, plenty of legitimate tools need it to work. Password managers need it. Ad blockers need it.

But the permission itself doesn’t know the difference between you scrolling a news site and you filling out an invoice with a client’s billing address. If an extension has that access, it technically can see both.

Now, this definitely does not mean every extension you have installed is spying on you. Most developers build the thing, it works fine, and nothing bad ever happens. The risk is more about what could happen over time: an extension gets sold to a new owner, a developer’s account gets compromised, or an old project stops getting maintained and picks up a vulnerability that nobody will fix. Forgetting an old extension could potentially expose you to malicious actors.

Why this matters more for home offices

If you work from an office with shared IT support, someone else is usually keeping an eye on what gets installed on work machines. At home, it’s just you and your browser, and the line between “personal browsing” and “handling client data” often lives on the exact same tab.

Browser extensions aren’t inherently dangerous or bad to have. The problem is that most of us install them casually, for personal reasons, on the same browser we use to send invoices, log into client accounts, or perform other sensitive work tasks on.

What you can do about it

You don’t need to swear off extensions or start researching every developer’s background. Just one annual cleanup should handle most of the risk!

Give client work its own browser profile

Most browsers let you create separate profiles, each with its own extensions, bookmarks, and logins, without needing separate software or accounts. Chrome, Firefox, and Edge all have this built in under the profile or “add person” menu.

Set up one profile for client work and invoicing, kept clean with only the extensions you actually need for that. Use a second profile for everything else, personal email, shopping, whatever extensions you like to collect. It takes a few minutes to set up and none of it requires new software or tools!

This one change does more than a permissions audit ever will, because it means even if something sketchy ends up in your personal profile, it has no access to the tab where you’re handling client payments.

The big takeaway from this advice

You don’t have to become suspicious of every tool you install. Extensions can legitimately make browsers much more useful, and most of them do exactly what they say. The point is just to know what has access to your browser, clear out what you don’t use, and keep client-facing work in its own lane. Keeping that in mind can greatly reduce risk and leave you using your browser extensions with more peace of mind.