Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsGrammarly and QuillBot Are Among Widely Used Chrome Extensions Facing Serious Privacy Questions
Grammarly and QuillBot Are Among Widely Used Chrome Extensions Facing Serious Privacy Questions
CybersecurityAI

Grammarly and QuillBot Are Among Widely Used Chrome Extensions Facing Serious Privacy Questions

•January 28, 2026
0
Help Net Security
Help Net Security•Jan 28, 2026

Companies Mentioned

QuillBot

QuillBot

Grammarly

Grammarly

Google

Google

GOOG

Why It Matters

The findings reveal a hidden data‑exfiltration vector that can compromise corporate confidentiality and personal privacy, prompting enterprises to reassess extension policies and regulators to consider stricter oversight.

Key Takeaways

  • •Grammarly and QuillBot collect extensive user data.
  • •Scripting and activeTab permissions enable code injection.
  • •Half of AI extensions gather personally identifiable information.
  • •Programming helpers pose highest average privacy risk.
  • •Translator tools have broad access but low misuse signals.

Pulse Analysis

The 2026 Incogni privacy risk report surveyed 442 AI‑powered Chrome extensions, revealing a systemic exposure that extends far beyond niche tools. Every extension required at least one permission, many granting the ability to read page content, monitor tab activity, or inject scripts. Such capabilities give the extensions visibility into emails, internal dashboards, and cloud applications, effectively turning a simple browser add‑on into a potential data conduit. With 52 % of the extensions collecting user data, the study underscores a broader industry blind spot: users rarely understand the depth of access they grant.

The report singled out two household names—Grammarly and QuillBot—as the most potentially damaging in terms of privacy. Both services harvest website content, keystrokes, navigation events, and even location data, while relying on the powerful scripting and activeTab permissions that let them modify pages in real time. For enterprises, this creates a hidden attack surface: confidential documents or proprietary code typed into web‑based editors can be captured and transmitted to external servers. The low malicious‑use likelihood score does not mitigate the risk posed by the sheer volume of users and the breadth of data accessed.

Categories such as programming assistants, meeting transcribers, and translators exhibit similar permission profiles, combining broad script access with modest declared data‑collection policies. Organizations can reduce exposure by enforcing extension whitelists, conducting regular permission audits, and educating employees about the trade‑off between convenience and privacy. Regulators are beginning to scrutinize AI‑driven browser tools, and future legislation may require more transparent disclosures and stricter data‑handling standards. Until such safeguards become mandatory, the onus remains on both developers to limit unnecessary permissions and on users to stay vigilant.

Grammarly and QuillBot are among widely used Chrome extensions facing serious privacy questions

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...