Google Beefs Up Privacy Rules for Chrome Extensions; Researcher Discovers New Loophole to Detect Incognito Mode

The new changes for Chrome extensions will go into effect starting October 15.

Advertisement
By Jagmeet Singh | Updated: 24 July 2019 14:13 IST
Highlights
  • Chrome extensions will be required to request access to least user data
  • Google has provided guidelines for developers to adopt new changes
  • Incognito Mode flaw has been detected in Storage Quota Management API

Google has expanded the requirement of posting privacy policies for Chrome extensions

Google has updated its User Data Policy to beef up privacy rules for third-party Chrome extensions. The new move comes as a follow-up on the Project Strobe update that the search giant announced back in late May. The Project Strobe is aimed to impose a root-and-branch review of third-party developer access to user data. In a separate development, a security researcher has found a way to detect Incognito Mode without leveraging the FileSystem API loophole that Google is set to fix through Chrome 76 later this month.

As a result of the new changes to the User Data Policy designed for Chrome Web Store, all third-party Chrome extensions will be required "to only request access to the least amount of data". Google earlier encouraged developers to request access to the least amount of data, but the new change has come into force as a requirement for all extensions.

Google has also expanded the requirement of posting privacy policies for Chrome extensions. Previously, extensions that handle personal and sensitive user data were required to post a privacy policy.

Advertisement

"Now, we're expanding this category to include extensions that handle user-provided content and personal communications. Of course, extensions must continue to be transparent in how they handle user data, disclosing the collection, use, and sharing of that data," Alexandre Blondin and Swagateeka Panigrahy of Chrome Product and Policy team noted in the blog post.

Advertisement

The two new changes to the User Data Policy of Chrome Web Store will go into effect starting October 15. Meanwhile, Google has provided guidelines for developers to make their extensions ready for the new change.

"After October 15, 2019, items that violate these updates to the User Data policy will be removed or rejected from the Web Store and will need to become compliant to be reinstated," the Chrome Product and Policy team members said.

Advertisement

The guidelines ask developers to either inventory the current permissions of their Chrome extensions or switch to alternatives that are "more narrowly scoped." A list of permissions used and the reasons behind their requirement should be included in the Chrome Web Store listing or within an about page section of the extension. Also, developers are required to request the new permission in the updated version of the extension if they expand the features of their extension or require new permission from end users.

For all extensions that handle "Personal or Sensitive User Data", including user-provided content and personal communications, the guidelines note that a privacy policy is mandatory. Google also asks developers to handle the user data securely, including transmitting it via modern cryptography.

Advertisement

Aside from the changes designed for Chrome extensions, Google is also bolstering the Incognito Mode of its Chrome browser by updating its FileSystem API. The change, which was announced last week, will be a part of Chrome 76 that's releasing on July 30. But ahead of the formal release, security researcher and PhD student Vikas Mishra claims to have found another loophole that makes the Incognito Mode trackable.

The new loophole has been spotted in the Storage Quota Management API that is designed to let Web apps understand how much temporary storage space they can use on the browser and how much of the allotted space remains available.

The researcher explains that in the regular browsing mode, a Web app can use a maximum of 1GB, which is 50 percent of the total available space available to all Web apps. When switched to the Incognito Mode, the storage allotment reduced to a maximum of 120MB. Now, the researcher says that for getting 120MB of storage quota in non-Incognito Mode, the Web app should be used on a system with a 2.4GB hard drive that is not common nowadays.

It is, thus, safe to presume that developers would be able to track the status of the Incognito Mode on Chrome browser if a Web app reports only having up to 120MB of allocated storage space using the Storage Quota Management API.

However, it is worth mentioning here that developers leveraging the loophole within the Storage Quota Management API would only be able to detect whether a user is on the Incognito Mode or using the regular browsing mode. This means the reported flaw won't provide any access to user data or browsing patterns.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones Soon
  2. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  3. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  4. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  5. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  6. Best Mobiles Under Rs. 60,000 in India
  7. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  8. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  9. iQOO 15 Live Image Leaked; Company Reveals Display Details
  10. How to Join the Viral Nano Banana and Saree Trend: The Gemini Prompts You Need
  1. The Witcher Season 4 Release Date Revealed: Know When and Where to Watch It Online
  2. iOS 26 Update Released Alongside iPadOS 26 and macOS Tahoe: Check Eligible Models, How to Download
  3. Scientists Propose Space Missions to Chase Down Interstellar Comets
  4. Iceland Plume Discovery Reveals Ancient Volcanic Funnels Across North Atlantic
  5. Huawei Watch Ultimate 2 Design Renders Leaked, Could Launch Soon
  6. Marvel's Wolverine Will Reportedly Launch in 2026; Insomniac's Venom Game in 'Active Development'
  7. US President Donald Trump Challenges Block on Removing US Fed’s Lisa Cook
  8. iPhone 17 Series Outpaces iPhone 16 in Demand While iPhone 17 Pro Max Tops Pre-Orders, Analyst Says
  9. iPhone 16 Remained Top Selling Smartphone For Second Consecutive Quarter Globally: Report
  10. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.