Skip to content

164news.com

  • Contact Us
  • Toggle search form

LinkedIn is secretly scanning your browser for 6,000 extensions, and you weren’t told

Posted on April 5, 2026 By 164news66 No Comments on LinkedIn is secretly scanning your browser for 6,000 extensions, and you weren’t told

LinkedIn’s Secretive Browser Extension Scanning: A Comprehensive Look

LinkedIn is secretly scanning your browser for 6,000+ extensions, and you weren’t told.

April 5, 2026 – 11:35 am

In short:
Every time you visit LinkedIn in a Chrome-based browser, a hidden JavaScript routine silently probes your browser for more than 6,000 installed extensions, collects 48 hardware and software characteristics about your device, encrypts the resulting fingerprint, and attaches it to every API request you make during your session. This practice, named "BrowserGate" by researchers, is not disclosed in LinkedIn’s privacy policy. LinkedIn claims it’s a security measure; critics argue it’s covert surveillance on a massive scale.

There exists a routine that operates undetected on your computer each time you open LinkedIn. You remain unaware of its presence and it isn’t mentioned in the company’s privacy policy. An investigation published in April 2026 by Fairlinked e.V., an European association of commercial LinkedIn users, revealed that LinkedIn injects a massive 2.7-megabyte JavaScript bundle into its website. This script silently scans visitors’ browsers for over 6,000 specific Chrome extensions, assembles a detailed device fingerprint, encrypts it, and transmits the data to LinkedIn’s servers, appending it to every subsequent action taken during the session.

This investigation, independently confirmed by BleepingComputer through testing, has been coined "BrowserGate." LinkedIn disputes several aspects of the report, though the technical details are generally agreed upon.

What the script does:

LinkedIn refers to its scanning system as "Spectroscopy." Upon loading the LinkedIn website, the script initiates up to 6,222 simultaneous requests, each targeting a specific browser extension by attempting to access associated files. The presence (or absence) of these files confirms whether an extension is installed. This operation occurs entirely in the background, without any visible prompts or notifications.

Beyond extensions, the script collects:

  • CPU core count
  • Available memory
  • Screen resolution
  • Timezone
  • Language settings
  • Battery status
  • Audio hardware information
  • Storage capacity

…and 40 additional device characteristics. This collective data creates a unique fingerprint capable of identifying a user even after clearing cookies.

Once compiled, the data is converted to JSON, encrypted with LinkedIn’s RSA public key (identifier: "apfcDfPK"), and transmitted to telemetry endpoints like li/track and /platform-telemetry/li/apfcDf. This fingerprint is then permanently embedded as an HTTP header in every API request made during the session, accompanying searches, profile views, and messages sent.

What it is looking for:

The script seeks to identify a wide range of browser extensions, many related to productivity, privacy, and security tools.

Clock

Post navigation

Previous Post: Affordable Plumbing Repair Denver: A Guide to Choosing the Perfect Wall Clock for Your Home
Next Post: Microsoft calls Copilot ‘entertainment only’ while charging $30 a month for it

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Editor's Picks

  • Long Island Real Estate Dispute Resolution
  • Commercial Plumbing Installation Denver
  • Denver Plumber for Emergency Services
  • Denver Gas Line Replacement
  • Affordable Plumbing Repair Denver
  • Leak Detection Services Denver CO
  • Sewer Backup Cleanup Denver Colorado
  • Expert Drain Snaking Denver
  • Plumbing for New Construction Denver
  • Sustainable Plumbing Solutions Denver

Recent Posts

  • BYD has built China’s first 4nm driving chip, and it’s putting LiDAR on a $10,000 car
  • Anthropic’s Milan office lands with Generali, Pirelli and Enel as named Italian customers
  • The hybrid model: why the smartest finance teams aren’t going all-in on AI
  • Oura’s Ring 5 is 40% smaller than its predecessor, and it arrives three days before a likely IPO filing
  • Waymo’s new Ojai robotaxi is cheaper to build, harder to break, and made in China

Recent Comments

  1. g555gameapk on Repairing a Leaking Denver Basin Augmentor: A Comprehensive Step-by-Step Guide
  2. xbet100 on Repairing a Leaking Denver Basin Augmentor: A Comprehensive Step-by-Step Guide
  3. hh55betcc on Repairing a Leaking Denver Basin Augmentor: A Comprehensive Step-by-Step Guide
  4. 5sbetwin on Expert Advice on Choosing the Right Sewer Backup Repair Company in Denver, Colorado
  5. 5sbet1 on Expert Advice on Choosing the Right Sewer Backup Repair Company in Denver, Colorado

Archives

  • May 2026
  • April 2026
  • March 2026

Editor's Picks

  • Long Island Real Estate Dispute Resolution
  • Commercial Plumbing Installation Denver
  • Denver Plumber for Emergency Services
  • Denver Gas Line Replacement
  • Affordable Plumbing Repair Denver
  • Leak Detection Services Denver CO
  • Sewer Backup Cleanup Denver Colorado
  • Expert Drain Snaking Denver
  • Plumbing for New Construction Denver
  • Sustainable Plumbing Solutions Denver

Copyright © 2026 164news.com.

Powered by PressBook Dark WordPress theme