Hacker News new | ask | show | jobs
by kevingadd 2300 days ago
Sadly they do because security holes or bugs can be found in extensions, and those can affect third-party websites. Project Zero has found many bugs of that sort and getting them patched on users' machines is very important.

If the extensions' permissions are extremely limited the risk profile becomes low, but that makes them far less useful.