Browser Extension Security Audit
Browser extensions are small software applications that run inside the browser. Depending on their permissions, they can access websites, browsing history, copied information or page content — including conversations with AI chat services. Use this audit to identify what is installed, confirm whether it is justified and decide what should be approved, restricted or removed.
This audit is vendor-neutral. It works for Microsoft Edge, Google Chrome, Mozilla Firefox and other Chromium-based browsers. It applies to managed business devices, partially managed environments and small organisations without enterprise browser-management software.
Use it to decide which extensions are genuinely required, appropriately trusted and correctly controlled — especially where staff use AI chat services from business browsers.
Step 1: Create the inventory
Record the following for each installed extension:
- □ Extension name
- □ Extension ID
- □ Browser
- □ Version
- □ Developer
- □ Store link
- □ User or device
- □ Date installed
- □ Business owner
- □ Business purpose
- □ Installation source (store, manual, policy)
- □ Current store status
In Chrome, visit chrome://extensions. In Edge, visit edge://extensions. In Firefox, visit about:addons. Centrally managed browsers may provide a policy-level extension report.
Step 2: Confirm the business need
For each extension, ask:
- □ What business problem does this extension solve?
- □ Is the feature already available in the browser or another approved application?
- □ Who requested it and when?
- □ Is it used regularly?
- □ Is there an approved alternative?
- □ What happens if it is removed?
A useful test
Convenience alone does not justify unrestricted access to business browsing data.
Step 3: Review permissions
Check whether the extension can:
- □ Read and change data on all websites
- □ Access specific websites (note which ones)
- □ Read browsing history
- □ Manage downloads
- □ Access clipboard data
- □ Read open tabs
- □ Change search settings
- □ Communicate with other applications
- □ Run in private browsing
- □ Access AI-chat websites
Mark each permission as: required for its purpose — excessive but tolerable — unclear — or prohibited for business use.
Broad permissions indicate capability — not necessarily malicious behaviour. The question is whether the access is justified by the extension’s actual purpose.
Step 4: Check the developer
- □ Developer identity confirmed
- □ Credible company website with support contact
- □ Privacy policy available and readable
- □ Security contact available
- □ Ownership history reviewed
- □ Extension has a clear and recent update history
- □ Extension has not been removed from the store
- □ No credible security warnings found
Popularity and positive reviews are useful context, but they are not security approval.
Step 5: Review data handling
- □ Information collected is clearly described
- □ Purpose of collection is explained
- □ Analytics are disclosed
- □ Commercial sharing or data-broker use is addressed
- □ Data retention is stated
- □ Data location is understood where relevant
- □ Subprocessors are identified where appropriate
- □ Business use is explicitly permitted
- □ Confidential information would be protected under the terms
Step 6: Assess the risk
| Lower risk | Medium risk | Higher risk |
|---|---|---|
| Narrow permission scope | Broad permissions with legitimate need | Access to all websites |
| Reputable and established developer | Incomplete privacy policy | Unclear or unverifiable developer |
| Clear business need | Access to business applications | No business owner recorded |
| No sensitive page access | Limited monitoring in place | AI-chat page access confirmed |
| Centrally managed | Clipboard or browsing-history access | |
| Commercial data sharing or data-broker use | ||
| Security warning or removed store listing | ||
| Unexpected ownership change | ||
| Installed without approval |
Step 7: Decide
Choose one outcome for each extension:
- □ Approve
- □ Approve with restricted website access
- □ Approve for limited users only
- □ Replace with an approved alternative
- □ Remove
- □ Block by extension ID
- □ Escalate for technical review
Record the decision, the approver, the date, any conditions and the next review date.
Step 8: Enforce the decision
- □ Unapproved extension removed or blocked
- □ Extension ID blocked in browser policy where appropriate
- □ Approved extensions allow-listed centrally
- □ Installation rights restricted to prevent self-installation
- □ Personal browser profiles reviewed
- □ Private-browsing extension access reviewed
- □ Related extensions on the same device checked
- □ Security monitoring updated
- □ Affected users notified
Step 9: Review regularly
- □ New extensions discovered since last review
- □ Version changes reviewed
- □ Permission changes reviewed
- □ Ownership changes reviewed
- □ Privacy-policy changes reviewed
- □ Store status checked
- □ Security alerts checked
- □ Business need reconfirmed
- □ Approval renewed or withdrawn
AI chat safety panel
Before entering information into an AI service, confirm:
- □ The AI service is on the approved list
- □ The business account type is approved
- □ The browser is managed or controlled
- □ Installed extensions have been reviewed
- □ The information is permitted for AI use
- □ Personal data has been removed where required
- □ No password, secret or API key is included
- □ Any confidential document is authorised for AI use
- □ The user knows how to report a mistake
The combination that matters
Approved AI plus unmanaged browser extensions does not equal approved AI use.
Want the full explanation?
Read our Technology Intelligence article on how browser extensions may access AI-chat conversations and the controls businesses should put in place:
Could a Browser Extension Be Reading Your AI Conversations? →
Plain-English Takeaway
Treat browser extensions as business software. Identify what is installed, confirm the business need, review the permissions and remove anything that is unnecessary or cannot be trusted. Staff should use approved AI services from managed browsers and should never enter confidential information unless the organisation has authorised that use.
Downloadable guide
Download the Browser Extension Security Audit
A printable checklist for identifying browser extensions, reviewing their permissions and deciding which should be approved, restricted or removed.
Download PDFFree download. No email address required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Safe Use of Generative AI at Work
Simple rules to help staff use AI tools without exposing business or customer data.
View guideRemote Working Security Checklist
The security basics to check for staff working from home or on the move.
View guideAI Policy Starter Guide
The starting points for a sensible, plain-English AI policy for a small business.
View guide