Data Protection

New Firefox Extensions Required to Disclose Data Collection Practices

All new extensions will be required to declare their data collection practices in their manifest file using a specific key.

Firefox security

Starting next week, all new Firefox extensions will be required to declare their personal data collection and transmission practices in the manifest file using a specific key, Mozilla announced.

The change is meant to provide users with increased visibility into these practices during the extension installation process.

The change only applies to new extensions, and not to new versions of existing extensions, and involves the use of the browser_specific_settings.gecko.data_collection_permissions key when declaring data collection capabilities in the manifest.json file.

“Extensions that do not collect or transmit any personal data are required to specify this by setting the none required data collection permission in this property,” Mozilla explains.

An extension’s data collection practices will also be displayed on the addons.mozilla.org page, but only if it is publicly listed. Users will also see the information when navigating to the extension’s Firefox about:addons page, in the Permissions and Data section.

“If an extension supports versions of Firefox prior to 140 for Desktop, or 142 for Android, then the developer will need to continue to provide the user with a clear way to control the add-on’s data collection and transmission immediately after installation of the add-on,” Mozilla notes.

Advertisement. Scroll to continue reading.

Extensions that begin using the data_collection_permissions keys will be required to continue using them for all subsequent iterations. Extensions that are required to use the property but do not set it correctly can not be submitted to addons.mozilla.org for signing.

Starting next year, all Firefox extensions will be required to use the data_collection_permissions keys when declaring data collection capabilities, Mozilla announced.

Related: Hackers Target Perplexity Comet Browser Users

Related: Chrome 141 and Firefox 143 Patches Fix High-Severity Vulnerabilities

Related: Browser Extensions Pose Serious Threat to Gen-AI Tools Handling Sensitive Data

Related: Threat Actors Use SVG Smuggling for Browser-Native Redirection

Related Content

Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

Compliance

Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation.

Vulnerabilities

The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure.

Application Security

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.

Vulnerabilities

Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed.

Vulnerabilities

The browser updates address multiple memory safety bugs that could potentially lead to remote code execution.

Vulnerabilities

The browser refreshes resolve critical and high-severity vulnerabilities that could lead to arbitrary code execution.

Privacy

The vulnerability is tracked as CVE-2026-6770 and it has been patched with the release of Firefox 150 and Tor 15.0.10.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version