Chrome wants more extension reviews, but good ratings won’t keep malware out
Chrome may soon make extension reviews easier to find, but strong ratings can still hide malicious behavior introduced through later updates or compromised listings.
Google is testing built-in extension review prompts, but good ratings can still hide malware
Chris DeGraw / Digital Trends
Google is preparing to add extension review links directly inside Chrome, putting feedback closer to the menus people already use to manage their add-ons.
A Chromium change, first spotted by Windows Report, points to review options in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would qualify, and the feature is still under development.
That could make newer complaints easier to find. It won’t fix the more serious problem that an extension’s rating may reflect an older, safer version rather than what’s currently running in someone’s browser.
Where Chrome would surface reviews
The planned feature would place review shortcuts inside Chrome instead of requiring users to search for an extension’s Web Store page. Selecting one would likely open the listing so the user can leave feedback.
AS Photography / Pexels
Google appears to be excluding unpacked, unpublished, removed, and policy-violating extensions. The feature also sits behind an experimental Chrome flag and couldn’t yet be triggered in Canary, so its final design and rollout remain unclear.
This is still a feedback feature, not a new security layer. Chrome isn’t scanning extensions differently or warning users that an add-on has turned malicious. It’s simply making the existing review process more visible.
Why good reviews can mislead you
Chrome extensions are repeat malware targets because they can gain broad browser access and keep it after earning a trustworthy reputation.
Microsoft recently uncovered 119 malicious extensions tied to its StegoAd campaign, with as many as 2.6 million installations. Many performed the task they advertised and delayed their malicious behavior, helping them look legitimate before hidden payloads activated.
Google Chrome
A strong average score may therefore describe the extension people installed months ago, not the version available now.
What Chrome users should watch for
More visible review links could help users spot a sudden change in sentiment after an update. A wave of complaints about redirects or unexplained behavior is far more useful than a polished rating built from years of older feedback.
Reviews still can’t inspect code or guarantee safety. They work best as an early warning, especially when recent comments sharply contradict the overall score.
Google hasn’t confirmed when the prompts will reach stable Chrome. Until then, anyone concerned about an installed extension will still need to check its Web Store page manually and read the newest reviews rather than trusting the headline rating.

Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Apple will finally stop making iPhone-to-Windows copy-paste such a chore
Your iPhone may finally copy and paste with a Windows PC like it should
Copying something on an iPhone and pasting it onto a Windows PC should be one of the least remarkable features imaginable. While this simple process seems effortless between an iPhone and Mac, Windows users are still left waiting.
Now, Microsoft is formally asking Apple to provide interoperable clipboard access through the company’s European Union interoperability process. The request, submitted on March 25, argues that iOS restrictions prevent third-party platforms from creating an experience comparable to Apple’s Universal Clipboard. Apple has now reached Phase III and committed to developing a solution.
Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Google’s “uncopyable” passkeys may be easier to steal than promised

Passkeys have been pushed as the safer successor to passwords. It promised protection from phishing, credential reuse, and password leaks. Google even claims that it cannot be copied or accidentally handed to someone else. But it might not be as secure as the company wants it to be.
Security researchers (Via BleepingComputer) have now found three ways malware can undermine those promises for passkeys synced through Google Password Manager. The techniques, collectively named Pass-ta-key, target Google Password Manager inside Chrome on Windows computers equipped with a Trusted Platform Module. Every attack requires malware to already be running on the victim’s computer.
Apple’s OpenAI lawsuit just tripped over an embarrassing wrong-recipient email
Apple came for OpenAI’s trade secrets, but OpenAI had email receipts

Apple and OpenAI’s legal battle has quickly moved beyond carefully worded court statements. OpenAI has just shared the email and message trails behind the dispute, and one exchange leaves Apple’s version of events looking questionable.
In a bluntly titled post, “Apple is getting this wrong,” OpenAI challenged Apple’s request for a preliminary injunction and accused the iPhone maker of building parts of its case around false or incomplete information. Apple wants a court to prevent OpenAI and two former Apple employees from accessing, acquiring, using, or disclosing its alleged confidential information.
ValVades