Knowledge Centre
Cyber Security GuidesChecklist and Guide

Browser Extension Security Audit

10 minutes to completeEvergreen guide — kept up to date

Browser extensions are small software applications that run inside the browser. Depending on their permissions, they can access websites, browsing history, copied information or page content — including conversations with AI chat services. Use this audit to identify what is installed, confirm whether it is justified and decide what should be approved, restricted or removed.

This audit is vendor-neutral. It works for Microsoft Edge, Google Chrome, Mozilla Firefox and other Chromium-based browsers. It applies to managed business devices, partially managed environments and small organisations without enterprise browser-management software.

Use it to decide which extensions are genuinely required, appropriately trusted and correctly controlled — especially where staff use AI chat services from business browsers.

Step 1: Create the inventory

Record the following for each installed extension:

  • □ Extension name
  • □ Extension ID
  • □ Browser
  • □ Version
  • □ Developer
  • □ Store link
  • □ User or device
  • □ Date installed
  • □ Business owner
  • □ Business purpose
  • □ Installation source (store, manual, policy)
  • □ Current store status

In Chrome, visit chrome://extensions. In Edge, visit edge://extensions. In Firefox, visit about:addons. Centrally managed browsers may provide a policy-level extension report.

Step 2: Confirm the business need

For each extension, ask:

  • □ What business problem does this extension solve?
  • □ Is the feature already available in the browser or another approved application?
  • □ Who requested it and when?
  • □ Is it used regularly?
  • □ Is there an approved alternative?
  • □ What happens if it is removed?

A useful test

Convenience alone does not justify unrestricted access to business browsing data.

Step 3: Review permissions

Check whether the extension can:

  • □ Read and change data on all websites
  • □ Access specific websites (note which ones)
  • □ Read browsing history
  • □ Manage downloads
  • □ Access clipboard data
  • □ Read open tabs
  • □ Change search settings
  • □ Communicate with other applications
  • □ Run in private browsing
  • □ Access AI-chat websites

Mark each permission as: required for its purpose — excessive but tolerable — unclear — or prohibited for business use.

Broad permissions indicate capability — not necessarily malicious behaviour. The question is whether the access is justified by the extension’s actual purpose.

Step 4: Check the developer

  • □ Developer identity confirmed
  • □ Credible company website with support contact
  • □ Privacy policy available and readable
  • □ Security contact available
  • □ Ownership history reviewed
  • □ Extension has a clear and recent update history
  • □ Extension has not been removed from the store
  • □ No credible security warnings found

Popularity and positive reviews are useful context, but they are not security approval.

Step 5: Review data handling

  • □ Information collected is clearly described
  • □ Purpose of collection is explained
  • □ Analytics are disclosed
  • □ Commercial sharing or data-broker use is addressed
  • □ Data retention is stated
  • □ Data location is understood where relevant
  • □ Subprocessors are identified where appropriate
  • □ Business use is explicitly permitted
  • □ Confidential information would be protected under the terms

Step 6: Assess the risk

Lower riskMedium riskHigher risk
Narrow permission scopeBroad permissions with legitimate needAccess to all websites
Reputable and established developerIncomplete privacy policyUnclear or unverifiable developer
Clear business needAccess to business applicationsNo business owner recorded
No sensitive page accessLimited monitoring in placeAI-chat page access confirmed
Centrally managedClipboard or browsing-history access
Commercial data sharing or data-broker use
Security warning or removed store listing
Unexpected ownership change
Installed without approval

Step 7: Decide

Choose one outcome for each extension:

  • □ Approve
  • □ Approve with restricted website access
  • □ Approve for limited users only
  • □ Replace with an approved alternative
  • □ Remove
  • □ Block by extension ID
  • □ Escalate for technical review

Record the decision, the approver, the date, any conditions and the next review date.

Step 8: Enforce the decision

  • □ Unapproved extension removed or blocked
  • □ Extension ID blocked in browser policy where appropriate
  • □ Approved extensions allow-listed centrally
  • □ Installation rights restricted to prevent self-installation
  • □ Personal browser profiles reviewed
  • □ Private-browsing extension access reviewed
  • □ Related extensions on the same device checked
  • □ Security monitoring updated
  • □ Affected users notified

Step 9: Review regularly

  • □ New extensions discovered since last review
  • □ Version changes reviewed
  • □ Permission changes reviewed
  • □ Ownership changes reviewed
  • □ Privacy-policy changes reviewed
  • □ Store status checked
  • □ Security alerts checked
  • □ Business need reconfirmed
  • □ Approval renewed or withdrawn

AI chat safety panel

Before entering information into an AI service, confirm:

  • □ The AI service is on the approved list
  • □ The business account type is approved
  • □ The browser is managed or controlled
  • □ Installed extensions have been reviewed
  • □ The information is permitted for AI use
  • □ Personal data has been removed where required
  • □ No password, secret or API key is included
  • □ Any confidential document is authorised for AI use
  • □ The user knows how to report a mistake

The combination that matters

Approved AI plus unmanaged browser extensions does not equal approved AI use.

Want the full explanation?

Read our Technology Intelligence article on how browser extensions may access AI-chat conversations and the controls businesses should put in place:

Could a Browser Extension Be Reading Your AI Conversations?

Plain-English Takeaway

Treat browser extensions as business software. Identify what is installed, confirm the business need, review the permissions and remove anything that is unnecessary or cannot be trusted. Staff should use approved AI services from managed browsers and should never enter confidential information unless the organisation has authorised that use.

Downloadable guide

Download the Browser Extension Security Audit

A printable checklist for identifying browser extensions, reviewing their permissions and deciding which should be approved, restricted or removed.

Download PDF

Free download. No email address required.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.