LinkedIn was reported to be running a hidden JavaScript fingerprinting script on its website that checks visitors’ browsers for 6,236 Chrome extensions and collects device characteristics including CPU core count, available memory, screen resolution, time zone, language settings, battery status, and storage capabilities. BleepingComputer said it independently verified the script’s presence and behavior, finding that it used randomized filenames and probed static resources associated with extension IDs to determine which add-ons were installed.
LinkedIn confirmed that it scans for extensions, saying the practice is intended to detect tools that scrape member data without permission, violate its terms of service, or generate unusual data-fetching activity that could affect platform stability. Reports said the extension list includes competing sales-intelligence tools such as Apollo, Lusha, and ZoomInfo, alongside unrelated categories like grammar and tax software, and noted the scope of the scanning had expanded from roughly 2,000 extensions to more than 6,000; questions remain about how the collected data is stored, linked to user identities, or used for enforcement.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
LinkedIn acknowledged that it scans for extensions, saying the practice is intended to identify tools that scrape member data without permission, violate its terms of service, or generate unusual data-fetching activity that could affect platform stability.
BleepingComputer said it independently confirmed the existence and behavior of the LinkedIn script, including its use of randomized filenames and requests for static resources associated with extension IDs to detect installed extensions.
Fairlinked e.V. reported that LinkedIn injects hidden JavaScript into page loads to probe for 6,236 installed Chrome extensions and collect browser and device characteristics for fingerprinting.
About two months before the April 2026 reports, a GitHub repository referenced in the coverage indicated the extension-detection list had grown to around 3,000 Chrome extensions.
According to the BrowserGate investigation, LinkedIn's active extension-detection list had grown to 5,459 entries by December 2025, indicating a major expansion of the browser-scanning system before the public April 2026 disclosures. The report says the list later increased further in early 2026.
The reported LinkedIn browser-scanning activity began at a smaller scale in 2025, when its hidden JavaScript was said to check for roughly 2,000 Chrome extensions on visitors' browsers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
8 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcezdnet.fr
Open sourcecio.com
Open sourcecio.com
Open sourcescworld.com
Open sourcehackread.com
Open sourcetomshardware.com
Open sourceghacks.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.