SECURE BROWSING CyberArtical Editorial Team

Before you install a security extension, read what it is asking for

A security dashboard listing checks such as networks are safe, virus free and apps up to date, with green ticks and amber warnings

Adding a security or privacy extension feels like unambiguous progress — a small, free improvement to a browser you already have. NCSC’s description of what an extension is permitted to do should give you pause before you click Add. Extensions "typically have permissions to read or change the data on any websites a user visits. This could include sensitive or personal data." That is the same access an attacker would want. Installing one is a decision about who you trust with it.

What you are actually agreeing to

  • NCSC: extensions "typically have permissions to read or change the data on any websites a user visits. This could include sensitive or personal data."
  • NCSC: extensions "increase the potential attack surface of your web browser, as this software may also contain security vulnerabilities."
  • NCSC: "Ensure automatic updates are turned on for both the browser and it’s extensions."
  • NCSC’s baseline is that browsers are "secure by default" — additions have to justify themselves against that.
  • FTC: obtain software only from legitimate sources, and keep your browser’s default security settings.

When this applies to you

Anyone about to install an ad blocker, a tracker blocker, a password tool, a privacy scorer, a coupon finder or anything else that promises to make browsing safer. It applies equally to extensions you were told to install by a support agent, a colleague or a video.

It is not an argument for having none. Some extensions earn their permissions. The point is that the calculation is not automatically favourable, and most people never make it at all.

The permission model, in one paragraph

A browser extension runs inside your browser with access granted at install time. The common grant is access to data on all sites you visit, which in practice means the contents of pages — including pages behind your logins, forms as you fill them, and anything displayed to you.

NCSC frames this two ways, and both matter. There is the trust question: the developer could read or change that data. And there is the code-quality question: the extension "may also contain security vulnerabilities", so even an honest developer adds attack surface. An extension that is later sold, abandoned or compromised carries its permissions with it.

The questions to answer before you click Add

  1. What problem am I solving, in one sentence? If the answer is "being safer generally", stop. NCSC’s position is that the browser is already secure by default.
  2. Does the browser already do this? Tracking protection, pop-up blocking, safe-browsing warnings and password storage are built into current browsers. A duplicate does not add protection; it adds permissions.
  3. What permissions is it requesting, and are they proportionate? A tool that only needs to act on one site should not be asking to read data on all of them.
  4. Who publishes it, and are they identifiable? The FTC’s rule for software generally is to obtain it only from legitimate sources. An anonymous publisher asking for read-and-change access across your whole browsing session is a poor bargain.
  5. Is it still maintained? Check the last update date. An extension that has not been updated in years still has all of its permissions and none of its fixes.
  6. Can I say what I would lose by not installing it? If not, the null option is the better one.

What to do immediately after installing one

  • Confirm automatic updates. NCSC’s requirement covers extensions as well as the browser. This is the single most important post-install step.
  • Restrict site access where the browser allows it. Most browsers let you change an extension from "on all sites" to "on click" or to a named list. Do that wherever the extension still works under the restriction.
  • Check whether it is enabled in private windows. That is usually a separate setting, and usually off by default for a reason.
  • Write down why you installed it. In six months you will not remember, and that is how extensions accumulate.

How often to come back to this

Twice a year is enough for most people, and moving house on a new machine is a natural moment to start from nothing rather than restoring the old set. The review is short: for each extension, can you still name the problem it solves and is it still being updated? Anything failing either test should be removed rather than disabled, because a disabled extension is one accidental click from being enabled again.

Removal is also the correct response to an extension that changes what it does after an update. NCSC’s warnings about attack surface apply to code that changes hands as much as to code that was always bad.

What this exercise does not address

Getting your extension list right does nothing about the two threats that actually reach most people. It will not stop you being sent to a convincing fake site — the FBI’s advice to check for misspelled or wrong domains is the control there, and its reminder that a lock icon proves nothing still stands.

And it does not touch what you deliberately give to services you use. That is a matter for the browser and device privacy settings the FTC describes, and for reading what you are being asked before you agree to it.

Sources: NCSC UK — Managing web browser security · FTC — How to recognize, remove and avoid malware · FBI IC3 — PSA I-061019 on the lock icon and HTTPS · FTC — How to protect your privacy online

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from NCSC UK, the FTC and the FBI. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories