Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

New Firefox Extensions Required to Disclose Data Collection Practices

All new extensions will be required to declare their data collection practices in their manifest file using a specific key.

Firefox security

Starting next week, all new Firefox extensions will be required to declare their personal data collection and transmission practices in the manifest file using a specific key, Mozilla announced.

The change is meant to provide users with increased visibility into these practices during the extension installation process.

The change only applies to new extensions, and not to new versions of existing extensions, and involves the use of the browser_specific_settings.gecko.data_collection_permissions key when declaring data collection capabilities in the manifest.json file.

“Extensions that do not collect or transmit any personal data are required to specify this by setting the none required data collection permission in this property,” Mozilla explains.

An extension’s data collection practices will also be displayed on the addons.mozilla.org page, but only if it is publicly listed. Users will also see the information when navigating to the extension’s Firefox about:addons page, in the Permissions and Data section.

“If an extension supports versions of Firefox prior to 140 for Desktop, or 142 for Android, then the developer will need to continue to provide the user with a clear way to control the add-on’s data collection and transmission immediately after installation of the add-on,” Mozilla notes.

Advertisement. Scroll to continue reading.

Extensions that begin using the data_collection_permissions keys will be required to continue using them for all subsequent iterations. Extensions that are required to use the property but do not set it correctly can not be submitted to addons.mozilla.org for signing.

Starting next year, all Firefox extensions will be required to use the data_collection_permissions keys when declaring data collection capabilities, Mozilla announced.

Related: Hackers Target Perplexity Comet Browser Users

Related: Chrome 141 and Firefox 143 Patches Fix High-Severity Vulnerabilities

Related: Browser Extensions Pose Serious Threat to Gen-AI Tools Handling Sensitive Data

Related: Threat Actors Use SVG Smuggling for Browser-Native Redirection

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

iCOUNTER has appointed Joel Molinoff as Chief Operating Officer (COO).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.