My first question with this is "why the hell can javascript even get this information in the first place? Seems like a major privacy issue, and probably a serious security one".

https://floss.social/@downey/116337415720027032

Michael Downey 🧢 (@[email protected])

🚨 LinkedIn runs a silent browser scan on every Chrome user who visits the site. 6,222 extensions. ~405 million users affected. No consent, no disclosure, no mention in their privacy policy. The scan identifies your sales tools, VPN, ad blocker, job search extensions, and extensions tied to religion, politics, and disability. The full technical breakdown, legal analysis, and searchable database of every scanned extension: https://browsergate.eu #LinkedIn #BrowserGate #privacy

FLOSS.social
elle (@[email protected])

since that browsergate site about LinkedIn seems to be gaining traction I figure I should mention: - yes, LinkedIn does do what's being claimed (though, it's that it probes for *specific* extensions you're running, using features in chrome's API - it doesn't "search your computer") - it does seem to have been doing this since at least as far back as [2017](https://github.com/dandrews/nefarious-linkedin), and there has been intermittent reporting on it over the years - I'm fairly confident the copy on the site was generated by (or at least went through) an LLM, so idk that this site is the best way to spread the issue around edit: and as [someone else noted in the replies](https://not-brain.d.on-t.work/notes/akl6hp4gjqcp8d7h), looking through the list of extensions of scans for... they're [pretty much all "AI"/scraper/automation plugins](https://browsergate.eu/extensions/). so, should LinkedIn be doing this, or even *able* to do this in Chrome? no! but also, it does seem like the stuff they're scanning for is all extensions that shouldn't exist to begin with tbh edit 2: please see [this follow-up post](https://social.treehouse.systems/@vantiss/116342005257886265) which proves this is just a shitty campaign by people who made an addon called "Teamfluence" that got blocked by LinkedIn

Treehouse Mastodon