LinkedIn Scans Chromium Browsers for 6,000+ Extensions
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- LinkedIn runs a hidden JavaScript that silently scans Chromium‑based browsers for over 6,000 installed extensions, encrypts the findings, and sends them to its own servers and third‑party recipients.
- Fairlinked e.V. uncovered the practice under its “BrowserGate” campaign, reporting that the scan targets 6,222 extension identifiers and includes categories such as job‑search tools, religious and political indicators, disability aids, and competitor products.
- The EU’s GDPR classifies data on religious belief, political opinion, and health as special‑category data, which LinkedIn collected without user consent or disclosure, violating the regulation.
- HUMAN Security (formerly PerimeterX) supplies an invisible tracking pixel that sets cookies on LinkedIn pages, further extending the data‑collection network beyond LinkedIn’s own scripts.
- LinkedIn has expanded its extension list from 461 in 2024 to over 6,000 by February 2026—a 1,252 % increase—and has used the data to issue legal threats against users of rival sales‑intelligence tools.
- EU regulators have been notified of the covert scanning and are preparing legal proceedings, while the combined user base of the targeted extensions reaches roughly 405 million people.
Why it matters: LinkedIn gains granular corporate intelligence by linking extension data to identified professionals, while users lose privacy and face unlawful processing of special‑category data under GDPR, exposing the platform to regulatory fines, legal challenges, and reputational damage, and giving competitors a potential legal foothold.