LinkedIn BrowserGate: Hidden Code Allegedly Scans 6,000+ Browser Extensions Without User Consent
An investigation by Fairlinked e.V. alleges LinkedIn silently scans users' browsers for over 6,000 extensions — potentially revealing religious beliefs, political views, and job-seeking activity — without user consent or disclosure in its privacy policy. LinkedIn firmly denies wrongdoing.

Illustration representing LinkedIn's alleged covert browser extension scanning exposed in the BrowserGate investigation, raising GDPR and enterprise privacy concerns
A significant privacy controversy has emerged involving LinkedIn, the world's largest professional networking platform with over one billion users. An investigation published by Fairlinked e.V., a European association of commercial LinkedIn users, alleges that the Microsoft-owned platform secretly scans users' browsers for more than 6,000 installed Chrome extensions — collecting sensitive data without user consent or any disclosure in LinkedIn's privacy policy.
The campaign, dubbed "BrowserGate," claims LinkedIn injects a 2.7-megabyte JavaScript bundle into its website that silently probes for specific extension identifiers, compiles a detailed fingerprint, encrypts it, and transmits the result to LinkedIn's servers. Independent testing by BleepingComputer confirmed the scanning script was active as of early April 2026.
The scope of what the scan allegedly reveals goes well beyond software preferences. Fairlinked identified high-risk data categories among the 6,222 tracked extensions, including 509 job search tools — potentially exposing users secretly seeking employment on the very platform where their current employer can see their profile — as well as extensions that identify practising Muslims, tools indicating political orientation, and applications used by neurodivergent users including those with ADHD and autism. The investigation also claims LinkedIn scans for over 200 products that compete directly with its own services, including Apollo, Lusha, and ZoomInfo — tools used widely by sales and recruitment teams across the GCC.
Under GDPR Article 9, processing data that reveals religious beliefs, political opinions, or health conditions is prohibited without explicit consent. Fairlinked alleges LinkedIn has no such consent mechanism and no valid exemption, and that the practice is not disclosed in the platform's public privacy policy. Independent legal experts consulted by Fairlinked argue the practice may constitute criminal liability under German law, in addition to GDPR exposure.
The data collected does not appear to stay exclusively with LinkedIn. Fairlinked claims it is transmitted to HUMAN Security — formerly PerimeterX — an American-Israeli cybersecurity firm, via a tracking element described as a zero-pixel iframe loaded off-screen and marked invisible. This claim has not been independently verified.
LinkedIn has firmly rejected the allegations. A company spokesperson told BleepingComputer: "The claims made on the website linked here are plain wrong." LinkedIn stated that the individual behind the investigation had their account restricted for scraping and other violations of its Terms of Service, and that its scanning is used solely to detect extensions that violate platform rules, protect user privacy, and maintain site stability. "We do not use this data to infer sensitive information about members," the spokesperson added. A German court sided with LinkedIn, denying the individual's request for a preliminary injunction.
For GCC enterprise security, legal, and compliance teams, the BrowserGate investigation raises three direct considerations. First, LinkedIn is extensively used by professionals, recruiters, and senior leaders across GCC governments, financial institutions, and regulated industries — many of whom may use the extensions now alleged to be scanned. Second, GCC organisations with European operations or EU data flows face GDPR exposure if the allegations are substantiated and employee LinkedIn usage involves the collection of special-category data. Third, the broader pattern — platforms collecting data invisible to users and undisclosed in privacy policies — is precisely the risk category that regulators under the UAE National Cyber Security Strategy 2025–2031 and Saudi Arabia's PDPL framework are increasingly focused on addressing.
Users wishing to check whether their installed extensions appear on LinkedIn's scan list can search the BrowserGate public database. Switching from Chromium-based browsers to Firefox is reported to meaningfully reduce but not fully eliminate exposure.
Note: The allegations in this article are disputed. LinkedIn has denied wrongdoing and a German court recently sided with the platform. MENA Cyber Wire presents both sides of the investigation.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.