Copy article

LinkedIn accused of scanning user browsers for installed extensions and collecting device data

ended 07. April 2026

A new report is alleging LinkedIn uses hidden JavaScript to scan its visitors’ browsers for installed extensions, looks for those that compete with its own sales tools, and then twists its users’ arms until they stop using those and pick LinkedIn’s products, instead.

However the social network says this is a smear campaign run by a disgruntled extensions developer who lost a court battle in Germany.

An “association of commercial LinkedIn users” called Fairlinked e.V published a report detailing “BrowserGate” - claiming LinkedIn scans for thousands of browser extensions and ties the results to identifiable user profiles - and by scanning, LinkedIn harvests personal and corporate information.

Make sure you caveat your comments why calling it accusations.

  • What is your reaction if this is true? 
  • What responsibility does LinkedIn have with regards to data?
  • Is this widespread by social media companies?

Responses this morning, we will be contacting LinkedIn for comment.

5 responses from the Newspage community

Copy all

Copy

These claims are still allegations, but LinkedIn is not denying the scanning itself; it’s defending why it was doing it. And that should make people sit up.
Because this is where tech firms love to get slippery. They act like the issue is only what they did with the data, when actually the first question is why they were poking around there in the first place. If users were not properly told, or the data grab went further than it needed to, that is where the real trouble starts.
For SMEs, this is the bit that matters in real life. Your team uses these platforms every day. If they are hoovering up more than people realise, that is not just a privacy problem; it is a trust problem.
Copy

Reports alleging that LinkedIn may be scanning browsers and profiling extension usage should be treated as claims, not established fact. LinkedIn disputes them. That distinction matters.

If the behaviour described is accurate, this goes beyond routine analytics. It suggests behavioural profiling using signals users did not knowingly provide, particularly if linked to identifiable accounts.

Platforms already operate with asymmetric visibility. They observe far more about user behaviour than users understand. Risk emerges when that visibility is used to influence decisions or commercial outcomes without clear consent.

Most users cannot audit this. Most organisations have no mechanism to detect it. Questions of scope and intent remain largely within self-regulation.

Platforms handling professional data at scale carry obligations beyond legal minimums. Consent must reflect actual data use, with independent audit and clear limits. Without that, trust becomes a claim.
Copy

LinkedIn has been battling a wave of tools bringing AI slop and spammy automation to the platform. If these accusations prove correct, LinkedIn users may not like that this has been happening without their knowledge or consent. The majority would probably support LinkedIn's efforts to rein in how much these tools are impacting the user experience, though.
Copy

Blocking user scraping tools harvesting valuable data is a fair reason for scanning extensions. A company like LinkedIn might argue it needs to detect scrapers to protect their users' data. The technical facts aren't contested, the other potential purposes are.

Scanning for other extensions that reveal religious practice, disability, or political orientation creates a dataset that, under GDPR, would typically require explicit consent to process. For a company that stores real names, employers, and job titles this could be considered identity profiling.

This isn't unprecedented. In 2021, eBay port scanned visitors' devices. Banking sites have similar scripts. Client-side surveillance has been creeping in for years across platforms. What makes this different is the scale (6000+ extensions), the specificity of what it reveals, and the fact that it could be happening on a platform where everyone uses their real identity, with links to a company that uses government ID checks to verify.
Copy

If these allegations are true, I would not call it a major shock. A lot of large platforms already collect browser, device and usage data to understand how people access their services and to protect their own commercial interests. That does not make it harmless, but it does mean LinkedIn would be part of a much wider pattern across the web.

The real issue is what happens next. If LinkedIn is collecting this kind of data and using it only for clearly stated security or product purposes, with proper transparency, that is one conversation. If it is being tied to user profiles, sold on, or used in ways people were never properly told about, that is much more serious and deserves regulatory scrutiny.

For a platform built on professional trust, the minimum standard should be openness. Users should be told exactly what is being collected, why it is being collected, and whether it is being used beyond basic platform operations. If LinkedIn cannot explain that clearly, concern is justified.