Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 20,2026

DGP.jpg

Karnataka DGP (Civil Rights Enforcement) K Ramachandra Rao was suspended with immediate effect, as per a state government order issued on Monday, 19 January. The order cited conduct unbecoming of a government servant and causing embarrassment to the state administration.

The Karnataka government suspended Rao after a purported video showed him in a compromising position with a woman inside his official chamber. The video went viral on social media. Rao rejected the videos outright, terming them "fabricated and false".

Who is K Ramachandra Rao?

Rao is a DGP-rank officer who was heading the Directorate of Civil Rights Enforcement until his suspension. He was promoted to DGP in September 2023 and assumed office in October 2023, the Sunday Guardian reported.

He also served as the Chairman and Managing Director of the Karnataka State Police Housing and Infrastructure Development Corporation Limited.

His stint as the Inspector General of Police (IGP) for the Southern Range was also marred by controversy. In 2014, during a cash seizure near Mysuru’s Yelwal, officials claimed the seized amount was ₹20 lakh, while the accused (Kerala-based merchants) claimed it was around ₹2.27 crore.

Rao, who was present during the seizure, denied all allegations. However, he was transferred soon after.

Allegations of collusion with a businessman surfaced, and a senior police officer was quoted by The Sunday Guardian as saying, “In Rao’s case, the CID has clearly mentioned that there was a great degree of lapse on the part of Rao and a deputy superintendent of police after it was brought to their notice that a few policemen, including a gunman attached to the IGP, were involved in the robbery.”

Rao had denied all wrongdoing in that incident. Despite past controversies, he rose to the state’s top police position, the Sunday Guardian reported.

Ranya Rao’s stepfather

Rao is the stepfather of Kannada actress Harshavardhini Ranya alias Ranya Rao, accused of orchestrating the illegal import of gold worth over ₹12.56 crore from Dubai to India along with two others — businessman Tarun Raju, and jewellery dealer Sahil Jain.

‘Obscene video’ controversy

A viral video showed Rao behaving inappropriately with a woman inside his office while in uniform.

The Karnataka government said in its Monday order that “vide videos and news reports widely broadcast on public news channels and media platforms, it is observed that Dr K Ramachandra Rao has acted in an obscene manner which is unbecoming of a Government Servant and also causing embarrassment to the Government.”

The order said the matter was examined by the state government, which found that the officer's conduct amounted to a violation of Rule 3 of the All India Services (Conduct) Rules, 1968.

The government said it is prima facie satisfied that "it is necessary to place Rao under suspension with immediate effect, pending inquiry".

During the suspension period, Rao will be entitled to subsistence allowance as per Rule 4 of the All India Services (Discipline and Appeal) Rules, 1969.

The order also places restrictions on his movement, stating that during the period of suspension, the officer must not leave headquarters under any circumstances without the written permission of the state government.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 20,2026

iran.jpg

Iranian security and intelligence forces have captured more than 470 individuals in three provinces, identified as key figures behind the recent wave of violent unrest and terrorist activities linked to foreign-backed networks.

The Intelligence Ministry's provincial office in Khorasan Razavi announced on Monday the arrest of 192 armed terrorists, identified as the main agents behind recent riots in the region. 

According to an official statement, the detainees were involved in the killing of several security personnel and civilians, setting fire to mosques, public service facilities, and buses, as well as attacks on military and law enforcement centers.

The seized items from the group include several bulletproof vests, Kalashnikov rifles, hunting weapons, Winchester rifles, and various cold weapons such as daggers, swords, brass knuckles, tactical knives, crossbows, and chains.

Evidence indicates that some of the individuals were tied to hostile movements and terrorist organizations, with links overseas. Others were identified as members of violent criminal gangs, actively taking part in the unrest alongside their associates.

Simultaneously, in the western province of Lorestan, the IRGC announced the arrest of 134 individuals as the main leaders and influential field agents of a US-Israeli terrorist network.

The IRGC statement stated that these individuals formed terrorist cells during the recent unrest, committing "Daesh-like" acts.

They wounded security forces with firearms and cold weapons, and burned and destroyed public and private properties, including mosques, shops, banks, and private and public vehicles.

In the northwestern province of Zanjan, the police reported detaining 150 people identified as principal leaders and agents behind recent riots.

Authorities noted that these individuals were responsible for destroying public and private property and intentionally setting fire to vehicles in the province's squares.

Their crimes include shedding the blood of innocent people, destroying public and private property, attempting to enter military sites, disrupting public order, and spreading terror among citizens.

A variety of cold weapons were reportedly seized from the detainees.

What began late last month as peaceful protests over economic hardship across Iran turned violent after public statements by US and Israeli regime figures encouraged vandalism and disorder.

During the unrest, foreign-backed mercenaries rampaged through cities, killing security forces and civilians and damaging public property.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 19,2026

New Delhi: Setting speculation to the rest, the CPI(M) has made it clear that it is open to have an electoral understanding with the Congress “to defeat” the Trinamool Congress and the BJP in West Bengal Assembly election even as it is all set to take on the grand old party in Kerala accusing it of “found wanting” in fighting the Hindutva forces.

The CPI(M) also said that it will contest the Tamil Nadu election “with DMK and its allies to defeat the BJP and its allies”, amid a section in the Congress triggering confusion about its participation in the M K Stalin-led coalition over demand over power-sharing and more seats. It is also willing to join hands with Congress and others in Assam and Puducherry to defeat the BJP.

The decisions came at a three-day meeting of the CPI(M) Central Committee in Thiruvananthapuram, which ended on Sunday after reviewing the poll preparations in the poll-bound states.

The CPI(M)'s decision came even as a section led by West Bengal Congress president Subhankar Sarkar is averse to tying up with the Left Front, claiming that their party is not benefitted by the electoral understanding. Both Congress and CPI(M)-led Left Front had electoral understanding in 2016 and 2021 Assembly elections and 2024 Lok Sabha polls.

Congress and the Left Front fought together for the first time in 2016 when Congress won 44 seats and the CPI(M) got 26. In 2021, the Left Front and the Congress drew a blank. In the 2024 Lok Sabha polls, Congress managed to win one seat while the Left did not win any. In the 2019 Lok Sabha polls, both fought against each other with Congress winning two and the Left none.

“In Bengal, the party will work for the defeat of both the TMC and the BJP, which are trying to polarise the society. We will try to rally all the forces that are ready to work against them,” the CPI(M) said in a statement without naming Congress by name. Senior leaders said there is no change in its strategy of pooling all non-BJP, non-TMC votes.

However, the party was critical of the Congress in Kerala where both will fight against each other.

The CPI(M) said it would "expose the BJP-led Union government’s denial of rightful dues to Kerala, the fiscal constraints imposed and the overall attack on federalism" as also "expose the failure of the Congress to effectively counter this attack on federalism, as the largest opposition party in the Parliament".

"The Congress, especially in Kerala, was found wanting in the fight against communal RSS-BJP, ideologically and this will also be exposed before the people," it added.

In Assam, it said, the CPI(M) will work for the mobilisation of all the anti-BJP parties and forces and defeat the rabidly communal and divisive BJP government. The Left parties are cooperating with Congress in the north-eastern state. In Puducherry, it said it will work for the defeat of the BJP alliance government.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.