{"id":11858,"date":"2026-04-04T10:03:38","date_gmt":"2026-04-04T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/04\/linkedin-hidden-code-secretly-searches-your-browser-for-installed-extensions\/"},"modified":"2026-04-04T10:03:38","modified_gmt":"2026-04-04T10:03:38","slug":"linkedin-hidden-code-secretly-searches-your-browser-for-installed-extensions","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/04\/linkedin-hidden-code-secretly-searches-your-browser-for-installed-extensions\/","title":{"rendered":"LinkedIn Hidden Code Secretly Searches Your Browser for Installed Extensions"},"content":{"rendered":"<p>    LinkedIn Hidden Code Secretly Searches Your Browser for Installed Extensions<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Every time you open LinkedIn in a Chrome-based browser, hidden JavaScript silently scans your computer for installed software without your knowledge, without your consent, and without a single word in LinkedIn\u2019s privacy policy.<\/p>\n<p>A revealing investigation conducted by the European advocacy group Fairlinked e.V., under the campaign name \u201cBrowserGate,\u201d has uncovered what researchers describe as one of the largest corporate espionage and data breach scandals in digital history.<\/p>\n<p>Microsoft\u2019s LinkedIn, the world\u2019s largest professional networking platform with over one billion users, is running covert code that probes visitors\u2019 browsers for thousands of installed extensions, compiles the results, encrypts them, and transmits everything back to LinkedIn\u2019s servers and to third-party companies.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-what-the-hidden-code-actually-does\"><strong>What the Hidden Code Actually Does<\/strong><\/h2>\n<p>The mechanism is technically precise and deliberately invisible. Each time a user loads a LinkedIn page, a fingerprinting script executes silently, probing for known browser extension identifiers by attempting to access files that extensions can optionally expose to websites. If a file loads, the extension is confirmed present. If not, it isn\u2019t. The entire scan takes milliseconds, and the user sees absolutely nothing.<\/p>\n<p>LinkedIn\u2019s JavaScript bundle contains identifiers for over 6,167 browser extensions. The scan is exclusively triggered on <a href=\"https:\/\/cybersecuritynews.com\/chromium-blink-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Chromium-based browsers<\/a> Chrome, Edge, Brave, Opera, and Arc \u2014 through a built-in <code>isUserAgentChrome()<\/code> function check. Firefox and Safari users are not currently affected.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhrSJux7k0hbZCdXlGpwAOU0lWIGtkNvR0z-2ZS2HYxYUWkR-DkjeW8Y3m9_ZBdHkzMAew-Xg7fd5WBPP9Bv39rfFxTQXEFWnDzV2361tMWVdCLbjsaClLAoq99HT8jz1iOyrhJboQkMVnCADxMevOLKU7RAKZkQrLv3M0AB63r1_y5bpf8-dplm0-KgxDl\/s16000\/Data%2520Flow%2520Summary.webp?ssl=1\" alt=\"\"><\/figure>\n<p>What makes this surveillance uniquely dangerous is context: LinkedIn accounts are tied to real names, employers, and job titles. Every detected extension is instantly matched to an identified individual.<\/p>\n<p>Because LinkedIn also knows where each user works, these individual scans aggregate into detailed corporate intelligence profiles revealing which software tools entire organizations use, without those organizations\u2019 knowledge or consent.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-sensitive-data-being-harvested\"><strong>The Sensitive Data Being Harvested<\/strong><\/h2>\n<p>The scope of what LinkedIn can infer from scanned extensions goes far beyond software preferences. <a href=\"https:\/\/browsergate.eu\/the-evidence-pack\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">BrowserGate researchers identified<\/a> the following high-risk categories among the 6,222 tracked extensions:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>509 job search tools<\/strong> \u2014 including extensions for Indeed, Glassdoor, and Monster \u2014 exposing users secretly looking for work on the very platform where their current employer can see their profile.<\/li>\n<li>\n<strong>Religious belief indicators<\/strong> \u2014 extensions that identify practicing Muslims and other faith communities.<\/li>\n<li>\n<strong>Political orientation markers<\/strong> \u2014 news source selectors and partisan fact-checking tools revealing users\u2019 political leanings.<\/li>\n<li>\n<strong>Disability and neurodivergent tools<\/strong> \u2014 ADHD management apps, autism support extensions, and screen readers.<\/li>\n<li>\n<strong>200+ direct competitor products<\/strong> \u2014 including Apollo, Lusha, ZoomInfo, and Hunter.io, which LinkedIn uses to map which companies use rival sales intelligence platforms.<\/li>\n<\/ul>\n<p>Under the EU\u2019s General Data Protection Regulation (GDPR), data revealing religious beliefs, political opinions, and health conditions is classified as Special Category Data, not merely regulated, but prohibited from processing without explicit consent. LinkedIn has no consent, no disclosure, and no legal basis for collecting it.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhzy4P8775XVmA7s2IZEjGgM9nQWJte2N9SYsL8xMjIUfsgFsM7wbYMBcuqrfU7RmHGVyXN1bL85jnRtt66GdyCLYmXv1YsnvMbP7AXuyW74sdYtKVA9n_o76b67E5IHXqPqA2ZknEd70yKCwRLVfdX1KgSlpCK4sZE_6vFeezhtLuzI2tVIU4CuCTOAEb1\/s16000\/linkedin%2520servers.webp?ssl=1\" alt=\"\"><\/figure>\n<p>The surveillance extends beyond LinkedIn\u2019s own servers. BrowserGate researchers identified an invisible tracking element loaded from HUMAN Security (formerly PerimeterX), an American-Israeli cybersecurity firm, a zero-pixel-wide element hidden off-screen that sets cookies without user knowledge.<\/p>\n<p>A separate fingerprinting script runs from LinkedIn\u2019s own servers, and a third script from Google executes silently on every page load. All of it is encrypted. None of it is disclosed.<\/p>\n<p>HUMAN Security\u2019s technology is embedded on hundreds of major websites, ostensibly to distinguish real users from bots, but BrowserGate contends the data flows back to third-party servers, building detailed device profiles of every visitor.<\/p>\n<p>The BrowserGate investigation further alleges that LinkedIn is leveraging its covert scanning capability for competitive enforcement. LinkedIn has already sent legal threats to users of third-party tools, using data obtained through this hidden scanning to identify and target those users.<\/p>\n<p>Simultaneously, LinkedIn dramatically expanded the scale of its surveillance. The scan list grew from roughly 461 products in 2024 to over 6,000 by February 2026 \u2014 a 1,252% increase \u2014 targeting precisely the tools the DMA was designed to protect.<\/p>\n<p id=\"h-the-company-also-alleged-that-the-browsergate-campaign-was-driven-by-someone-whose-account-had-been-banned-for-violating-linkedin-s-terms-of-service-3\">The company also alleged that the BrowserGate campaign was driven by someone whose account had been banned for violating LinkedIn\u2019s Terms of Service.<\/p>\n<p>Independent researchers, however, note this practice dates back to at least 2017, when LinkedIn was scanning for just 38 extensions. By February 2026, that number had grown to nearly 3,000, and has since more than doubled.<\/p>\n<p>Fairlinked e.V. states the practice is illegal and potentially criminal in every jurisdiction it has examined. The combination of undisclosed special-category data collection, covert third-party transmission, and alleged regulatory deception presents serious exposure <a href=\"https:\/\/cybersecuritynews.com\/ciso-compliance-guide\/\" target=\"_blank\" rel=\"noreferrer noopener\">under GDPR<\/a>, the ePrivacy Directive, and the DMA.<\/p>\n<p>The combined user base of the scanned extensions amounts to 405 million people \u2014 making BrowserGate one of the largest undisclosed data collection operations in the history of the commercial internet.<\/p>\n<p>Regulators across the EU have been notified. Legal proceedings are being organized. For now, every LinkedIn user on a Chromium browser remains a subject of this silent, daily scan.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself\"><strong>How to Protect Yourself<\/strong><\/h2>\n<p>Users concerned about the scanning have several immediate options:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Switch to Firefox or Safari<\/strong> for LinkedIn access \u2014 the detection method relies on Chrome\u2019s extension architecture, which Firefox\u2019s design prevents<\/li>\n<li>\n<strong>Create a LinkedIn-only Chrome profile<\/strong> with zero extensions installed, breaking the surveillance chain<\/li>\n<li>\n<strong>Use Brave browser<\/strong> with fingerprinting protection enabled, which blocks the detection mechanism<\/li>\n<li>\n<strong>Audit your installed extensions<\/strong> using BrowserGate\u2019s searchable public database to check if your tools are being tracked<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/linkedin-code-collects-data\/\">LinkedIn Hidden Code Secretly Searches Your Browser for Installed Extensions<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/linkedin-code-collects-data\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>LinkedIn Hidden Code Secretly Searches Your Browser for Installed Extensions Every time you open LinkedIn in a Chrome-based browser, hidden JavaScript silently scans your computer for installed software without your knowledge, without your consent, and without a single word in LinkedIn\u2019s privacy policy. A revealing investigation conducted by the European advocacy group Fairlinked e.V., under [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,83],"tags":[130],"class_list":["post-11858","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-privacy","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11858"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11858"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11858\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}