Your browser spellchecker could be leaking your passwords


Some extended spellchecking features added into Google Chrome and Microsoft Edge web browsers have been found to be leaking sensitive information back to their parent companies.
An analysis by JavaScript security firm otto-js (opens in new tab) found most users enable features that they believe to be beneficial to their productivity, only to find that they are leaking their own personal information such as usernames, emails, passwords, and more, to the browsers’ respective companies.
Both browsers have basic, built-in spellchecking features enabled by default, which do not transmit data back to Google or Microsoft. Chrome’s ‘Enhanced Spellcheck’ and Edge’s ‘Microsoft Editor’ are exclusively opt-in add-ons that users must explicitly authorize, and while it’s made clear that your data will be sent back to both companies to improve the products, it’s not so obvious that this could include your personally identifiable information (PII).
Chrome and Edge password leaks
Working in conjunction with most text fields on a webpage, both tools have access to “basically anything”, says otto-js. This means that any data you input online, including your date of birth, payment details, contact information, and login credentials could all be being sent back to Google and Microsoft.
Most websites that block out passwords online obscure this highly sensitive information from the spellchecking tools, but when a user clicks to uncover the text (maybe to check if they have typed it correctly), the information is subsequently exposed.
Bleeping Computer (opens in new tab) reported it found the transmission of usernames to SSA.gov, Bank of America, and Verizon, using Chrome, with passwords also being exposed to CNN and Facebook only when the ‘show password’ or equivalent button had been clicked.
One way to minimize exposure is for web developers to include “spellcheck=false” to any input fields that may require sensitive information, effectively blocking out those fields from spellchecking tools, though this will of course mean that spellchecking will be disabled in these entries.
On a user’s end, temporarily disabling enhanced spellcheckers or removing them entirely from a browser seem to be the only ways of protecting your data, at least until either company revises its privacy policy.
Audio player loading… Some extended spellchecking features added into Google Chrome and Microsoft Edge web browsers have been found to be leaking sensitive information back to their parent companies. An analysis by JavaScript security firm otto-js (opens in new tab) found most users enable features that they believe to be…
Recent Posts
- FTC Chair praises Justice Thomas as ‘the most important judge of the last 100 years’ for Black History Month
- HP acquires Humane AI assets and the AI pin may suffer a humane death
- HP acquires Humane Ai and gives the AI pin a humane death
- DOGE can keep accessing government data for now, judge rules
- Humane’s AI Pin: all the news about the dead AI-powered wearable
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010