Security

Malicious browser extensions in 2026: how to protect yourself

A critical flaw in Firefox, hundreds of fraudulent VPN extensions in Chrome, and campaigns stealing corporate credentials. Here's what to check in your browser right now.

Published on August 27, 2026 · The mitza.es team

August 2026 has brought several browser-related security alerts worth taking seriously, especially because the browser is, for most businesses, the gateway to email, invoicing, online banking and any management platform.

Critical flaw in Firefox

The vulnerability CVE-2026-8953 was identified in Firefox's accessibility component, with a CVSS score of 9.6 out of 10. The flaw allows an attacker to build a webpage specifically designed to compromise the browser's main process, or even the underlying operating system, just by visiting it.

737 fraudulent VPN extensions in Chrome

737 VPN extensions were detected in the Chrome Web Store impersonating well-known brands to intercept the traffic of anyone who installed them, redirecting browsing through servers controlled by the attackers themselves. The goal: spying on personal and browsing data under the promise of a free or cheap VPN.

Legitimate extensions turned into spying tools

The campaign known as ShadyPanda has used Chrome and Edge's own update system to turn legitimate, already-installed extensions into spying tools, without the user having to install anything new or grant any additional permission. It's the same underlying pattern we already saw with wp2shell on WordPress: exploiting a trusted channel, such as updates, to sneak in malicious code.

An increasingly common target: corporate credentials

In Spain, malicious Chrome extensions have been identified that are specifically aimed at stealing sensitive information in business environments, used as an entry point to compromise corporate accounts and gain unauthorized access to critical management platforms such as Workday, NetSuite or SuccessFactors. It's no longer just a risk for individual users: it's a direct route into a company's systems.

What to check in your business

  • Update Firefox and Chrome to the latest available version as soon as possible.
  • Review which extensions are installed on each of your business's computers and remove any you don't actively use.
  • Be especially wary of free VPN extensions from unclear sources.
  • Keep in mind that a trusted extension can turn malicious after an update, not only at the moment you install it.

Basic maintenance, once again the best defense

This connects directly with what we already explained about the critical Windows vulnerabilities and macOS this same month: the browser is one more component that needs active review and maintenance. Our IT maintenance service includes this review, and if you want a more complete diagnosis of your exposure, you can request a tailored audit.

Do you know which extensions are installed on your team's computers?

We review the security of your devices and browsers before a malicious extension becomes a real problem.

No spam. No sales calls. Just your personalised reply.