Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
December 4,2025

Udupi: A 40-year-old NRI from Udupi has reportedly lost more than Rs 12.25 lakh in an online investment scam operated through Telegram.

According to a complaint filed at the CEN police station, Leo Jerome Mendonsa, who has been working in Dubai for the past 15 years in computer accessories sales, maintains NRI accounts in Karkala and Nitte.

On November 12, 2025, Mendonsa was added to a Telegram group called Instaflow Earnings by unknown individuals. Users identified as Priya and Dipannita persuaded him to invest in “Revenue Tasks.” Initially, Mendonsa transferred Rs 1,100 multiple times and received the promised returns, encouraging him to continue.

On November 14, another user, Nishmitha Shetty, directed him to register on a website, digitvisionuoce.cc, and invest Rs 4 lakh in various shares. Over the next few days, he made multiple transfers totaling Rs 12,25,000, including Rs 50,000 via Google Pay, believing the scheme was legitimate.

After receiving the money, the alleged handlers stopped responding, and neither the invested amount nor the promised profits were returned.

The CEN police have registered a case under Sections 66(C) and 66(D) of the IT Act and Section 318(4) of the Bharatiya Nyaya Sanhita (BNS), and investigations are ongoing.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 27,2025

imrankhan.jpg

Authorities at Pakistan’s high-security Adiala Jail in Rawalpindi on Wednesday dismissed speculation about the condition of imprisoned former Pakistan Prime Minister Imran Khan, rejecting rumours that he had been moved out of the facility or was in danger. Officials said Khan was in “good health” and described the viral death claims as “baseless.”

“There is no truth to reports about his transfer from Adiala Jail,” the Rawalpindi prison administration said in a statement, according to Geo News. “He is fully healthy and receiving complete medical attention.”

Amid swirling rumours on social media, Imran Khan’s party, Pakistan Tehreek-e-Insaf (PTI), urged the federal government to issue an official clarification and demanded that authorities allow his family to meet him immediately, Dawn reported.

The frenzy began after Khan’s three sisters called for an impartial probe into what they described as a “brutal” police assault on them and other PTI supporters outside Adiala Jail last week. Soon after, several social media handles circulated unverified claims alleging that Khan had been “killed” inside the prison.

The rumours intensified when a handle named “Afghanistan Times” claimed that “credible sources” had confirmed Khan’s “murder” and that his body had been moved out of the jail — allegations that have not been verified by any credible agency.

Imran Khan, PTI’s patron-in-chief, has been lodged in the Rawalpindi prison since August 2023 in multiple cases. For over a month, an undeclared restriction has prevented family members and senior PTI leaders from meeting him. Khyber-Pakhtunkhwa Chief Minister Sohail Afridi has reportedly been denied access despite making seven attempts.

In a letter to Punjab Police Chief Usman Anwar, Khan’s sisters — Noreen Niazi, Aleema Khan, and Dr. Uzma Khan — said they were “peacefully protesting” outside the jail when police allegedly launched an unprovoked assault after streetlights were switched off.

“At 71, I was seized by my hair, thrown to the ground and dragged across the road,” Noreen Niazi said, alleging that other women present were also slapped and manhandled.

Adiala Jail officials reiterated that speculation over Imran Khan’s health was unfounded and insisted that his well-being was being ensured, Geo News reported.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 29,2025

DKSsiddu.jpg

New Delhi: Karnataka chief minister Siddaramaiah and deputy CM DK Shivakumar on Saturday put up a dramatic display of unity at a closely watched joint press briefing, firmly dismissing weeks of speculation about a power-sharing tussle within the Congress. With the high command nudging both leaders to sit together and settle the dust, the meeting became a political spectacle, ending with the duo declaring that there was “no confusion, no differences.”

Calling the reports of a rift “manufactured confusion,” Siddaramaiah said the talks had gone smoothly, even joking about their breakfast. “Breakfast was very good. All three of us enjoyed it,” he said. “We want to end this confusion once and for all. For local elections and for 2028, our mission is clear — Congress must return to power. There is no difference between me and DKS, not now, not before.”

He blamed the media for fuelling rumours and reiterated absolute adherence to the party leadership. “From tomorrow, let there be no confusion. What the high command says, we will follow.”

Siddaramaiah also assured that the Assembly session starting December 8 would run smoothly and vowed that Congress would take on the BJP and JD(S) “together.”

Shivakumar echoed the chief minister word for word, stressing loyalty and discipline. “People have given us a massive mandate. It is our duty to deliver,” he said. “This government was formed under Siddaramaiah’s leadership. We both have complete trust in the high command. If they tell me to wait, I will wait.”

He added that the two leaders had discussed strategy for the 2028 Assembly elections. “Whatever the CM says, I agree. We are loyal soldiers of the party. The party may be facing challenges nationally, but we will keep it strong in Karnataka.”

Shivakumar also said Siddaramaiah would soon visit his home for lunch or dinner — another symbolic gesture meant to underline their unity.

Both leaders later posted on social media describing the breakfast meeting as “productive” and focused on “Karnataka’s priorities.”

The BJP, however, rejected the show of camaraderie as “pure bunkum,” accusing Congress of trying to paper over an internal power struggle. But Siddaramaiah and Shivakumar insisted their united front would continue — and that there was “no confusion” within the state leadership.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.