What can a browser extension actually see?
Potentially everything you do in your browser — which makes extensions one of the most under-appreciated security risks on a personal computer.
What a permissive extension can access:
The content of every page you visit, including pages behind a login — your email, your banking interface, internal company systems. The extension runs inside the page after decryption, so HTTPS provides no protection against it.
Everything you type, including passwords, card numbers and messages.
Your full browsing history and open tabs.
Cookies and session tokens, which can allow account access without a password.
The ability to modify pages — inserting content, altering displayed information, or redirecting links.
Network requests, which can be observed or intercepted.
The permission warnings are the signal. "Read and change all your data on all websites" is the broadest, and an enormous number of extensions request it. Some genuinely need it — ad blockers and password managers must interact with every page. Many do not.
Why this is a live rather than theoretical risk:
Extensions are sold. A developer with a popular extension and an established user base receives purchase offers, and the buyer inherits every installed user. Updates install automatically and silently, so a benign extension can become malicious overnight without any user action.
Accounts get compromised, and attackers have pushed malicious updates through legitimate developer accounts.
Store review is imperfect, and malicious extensions repeatedly reach official stores.
Data harvesting is common even among functioning extensions, with browsing data sold to analytics firms.
Practical measures:
Install as few as possible, and audit periodically — most people have extensions they forgot.
Check permissions before installing and treat broad ones as a decision.
Restrict access per site where the browser supports it, or set an extension to activate on click.
Use a separate browser profile for sensitive activity with no extensions.