• Cyber Safety
  • Posts
  • Your Browser Extensions May Have More Access Than Your Employees

Your Browser Extensions May Have More Access Than Your Employees

In partnership with

Join CX leaders from Clay, Anthropic, and more at Pioneer

AI is fundamentally transforming CX, making perfect experiences possible. But there's no playbook for delivering them.

Join Pioneer on October 7th to explore how CX leaders are redefining what's possible with AI.

You’ll learn how some of the most innovative leaders from Clay, Anthropic, Gamma, and more are transforming their organizations and reinventing their operations.

Plus, you’ll hear from Fin product leaders on their vision for Fin and be the first to see what’s new.

Extensions Operate Inside a Trusted Environment

Browser extensions can interact directly with the applications employees use every day. Depending on their permissions, they may access browsing activity, webpage content, downloads, or data entered into websites.

One Extension Can Touch Multiple Business Systems

An employee might use the same browser for email, CRM, banking, cloud dashboards, and internal applications. A risky extension potentially sits alongside all of them.

Legitimate Extensions Can Change Over Time

An extension approved today may later change ownership, introduce new functionality, request additional permissions, or receive a compromised update.

Hire Ava, the AI BDR built for enterprise

Ava is the first AI BDR to run outbound end to end, finding leads or ingesting your CRM accounts, sending personalized emails on your reps' behalf, and booking meetings, autonomously or on copilot. She runs outbound for DoorDash and Grammarly. She's SOC 2 Type II audited, SSO and GDPR ready.

Convenience Encourages Permission Creep

Employees often install extensions for productivity, screenshots, AI assistance, writing, or automation without evaluating exactly what access those tools require.

Removing the Extension Isn’t a Complete Strategy

Organizations need visibility into which extensions are installed, which permissions they hold, and whether they remain necessary — especially on devices accessing sensitive systems.

Treat Extensions Like Software, Not Accessories

Create an approved extension policy, restrict unnecessary permissions, monitor installations, remove abandoned tools, and review high-risk extensions regularly. If software can read what happens inside your browser, it deserves the same scrutiny as software installed on your computer.

Is Your Training Data Actually Model-Ready?

DNSMOS gives you a score, not whether that data fits your model. Treat it as pass/fail and you'll train on audio that looks clean but hurts performance, while tossing good data for no reason. Voices' CTO DJ Jalali just published a white paper with the four-step framework the team uses to set internal thresholds instead.