Quick answer: a Chrome extension can only do what its permissions allow, and Chrome shows the risky ones as warnings when you install it. The warning to take most seriously is "Read and change all your data on all websites": it lets the extension see and modify every page you open, including what you type. Prefer extensions that ask for little, work on click (the activeTab permission) instead of on every site, and check Details > Site access on chrome://extensions to limit the ones you already have.
Extensions are some of the most useful software in a browser, and some of the most trusted. They run inside the same window as your email, your bank and your company's admin panels. Permissions are the line between "a tool that takes screenshots" and "a tool that can read everything on screen". Knowing how to read them takes five minutes and protects you for years.
How Chrome extension permissions work
Every extension lists what it needs in a file called the manifest. There are three kinds of request:
- API permissions unlock browser features, such as storage, downloads, history or contextMenus.
- Host permissions say which websites the extension can access, from a single domain to <all_urls>, which means every site.
- Optional permissions aren't granted at install. The extension asks for them later, when you use the feature that needs them.
When you install an extension, Chrome turns the risky requests into plain-language warnings in the Add extension dialog. Many permissions show no warning at all, because on their own they can't reach your personal data.
The warnings, from harmless to serious

These are the exact warnings Chrome shows, according to Chrome's permissions reference:
No warning. activeTab, scripting, contextMenus, storage, alarms, offscreen, sidePanel, identity, unlimitedStorage, cookies and webRequest show nothing at install. Some of them, like cookies and webRequest, only become powerful when combined with host permissions, which do show a warning.
Access to specific data or features:
- tabs, webNavigation: Read your browsing history
- history: Read and change your browsing history on all signed-in devices
- bookmarks: Read and change your bookmarks
- downloads: Manage your downloads
- clipboardRead: Read data you copy and paste
- clipboardWrite: Modify data you copy and paste
- topSites: Read a list of your most frequently visited websites
- geolocation: Detect your physical location
- notifications: Display notifications
- desktopCapture: Capture content of your screen
- privacy: Change your privacy-related settings
- management: Manage your apps, extensions, and themes
- nativeMessaging: Communicate with cooperating native applications
- declarativeNetRequest: Block content on any page
Access to every website: host permissions for all sites, and permissions such as proxy, tabCapture and debugger, show Read and change all your data on all websites.
Chrome also merges warnings. For example, the tabs warning isn't shown separately when an extension already asks for all sites, because that access already covers it. So a short warning list doesn't always mean a small set of permissions. It means the biggest one already covers the rest.
What "Read and change all your data on all websites" actually means
This is the warning that matters most, because it's the broadest. An extension with access to all websites can, on every page you open:
- read the page, including email, documents, chat messages and dashboards;
- read what you type into forms, including search boxes and, on many sites, passwords;
- change the page, for example by inserting content or altering links;
- send what it reads to its own servers.
Plenty of legitimate extensions need this. Ad blockers, password managers and accessibility tools all work on every site by design. The question isn't "is this permission bad?" but "does this tool need it to do its job?" A grammar checker plausibly needs to see what you type everywhere. A screenshot tool, a color picker or a tab counter doesn't.
activeTab: access only when you click
activeTab is the most privacy-friendly way for an extension to work with pages. It shows no warning, because it grants nothing at install. Access to the current tab is granted only when you invoke the extension: by clicking its icon, using its keyboard shortcut or choosing it from a menu. It's temporary, and it covers only that tab.
Tools that act on demand, such as screenshot tools, translators or page summarizers, can be built entirely on activeTab. When an on-demand tool asks for every website instead, ask why.
Before you install: read the request
1. Check the warnings in the Add extension dialog. If one doesn't match what the tool does, stop.
2. Read the Chrome Web Store listing's privacy section. Developers must declare what data they collect and how they use it.
3. Look at who publishes it. A real company, a website, a privacy policy and a support address are good signs. So is a long update history.
4. Prefer narrower alternatives. If two tools do the same job, pick the one that asks for less.
After you install: check and limit access
You can see and reduce what an installed extension can do:
1. Open chrome://extensions.
2. Click Details on the extension.
3. Under Permissions, read the list. Under Site access, choose:
- On click: the extension only runs on a site when you click its icon. This is the safest setting. - On specific sites: it runs automatically only on the sites you add. - On all sites: it can access every site it asked for.

Switching an all-sites extension to On click keeps it working for most on-demand tasks while removing its constant view of your browsing.
Updates can change permissions
Extensions update automatically. If an update asks for a new permission with a warning, Chrome disables the extension until you accept the new permission. Treat that prompt like a fresh install: if a simple tool suddenly wants access to every website, don't accept it, and look for news about the extension changing owners.
Updates that add permissions without a warning don't trigger the prompt, which is another reason to prefer tools whose core design doesn't need broad access.
Red flags checklist
- Asks for all websites but only works when you click it
- Wants history, tabs or clipboard access with no clear reason
- Unknown publisher, no website or privacy policy
- Very few users and reviews, or reviews mentioning ads or redirects
- A sudden permission prompt after an update
- A free tool whose business model you can't explain
For IT: control permissions across the company
On managed Chrome, administrators don't have to rely on every employee reading warnings:
- Allowlist instead of blocklist. Block all extensions by default and allow only the ones you've reviewed.
- Block by permission. The ExtensionSettings policy can block extensions that request specific permissions (blocked_permissions) and stop extensions from running on sensitive sites (runtime_blocked_hosts), such as your HR or finance systems.
- Force-install the approved tools so people don't go looking for riskier alternatives. See how to force-install a Chrome extension with Google Admin.
- Review the data flow, not just the permissions. Ask whether the extension sends anything to the developer's servers, and where.
Example: a screenshot tool that asks for little
Screshot captures the visible area or a full page, blurs sensitive data and annotates. It asks for three permissions, none of which shows an install warning:
- activeTab to capture the tab in front of you, only when you click the icon or use a shortcut;
- scripting to scroll that same tab during a full-page capture and put it back afterwards;
- contextMenus to add capture options to the right-click menu on its icon.
It requests no host permissions, so it can't read your other tabs or your browsing history, and capturing, blurring, copying and downloading upload nothing. Our security page explains every permission, and the security review pack has the answers IT reviewers usually ask for.
FAQ
Are Chrome extensions safe?
Most are, but an extension runs with the access you grant it. Install from known publishers, read the warnings, and prefer tools that ask for the least access they need.
Can a Chrome extension see my passwords?
An extension with access to a site can read what's on that page, including what you type into its forms. That's why access to all websites deserves the closest look.
Does an extension with no warnings have no permissions?
No. Several permissions, such as activeTab, storage and contextMenus, show no warning because they can't reach your personal data on their own. Check Details on chrome://extensions for the full list.
What's the difference between "On click" and "On all sites"?
On click lets the extension access a site only after you click its icon there. On all sites lets it access every site it requested, all the time, without asking.
Why did Chrome disable one of my extensions?
Often because an update asked for a new permission with a warning. Chrome keeps it off until you approve. Check what it's asking for before you accept.
How do I remove an extension?
Open chrome://extensions and click Remove, or right-click its icon and choose Remove from Chrome. Extensions installed by your organization can't be removed by users.
Sources
- Chrome for Developers: Permissions list
- Chrome for Developers: Permission warning guidelines
- Chrome for Developers: User controls for host permissions
- Chrome Enterprise: ExtensionSettings policy

Written by
Screshot TeamProduct & security team
The team that builds Screshot, the private screenshot tool for Chrome. We write about keeping customer data out of screenshots, rolling out tools across a company, and getting work done faster with your screen.
Keep customer data out of your screenshots
Screshot captures a screen or a full page, blurs sensitive details and annotates, all on your device. Free for every team.



