Skip to content
Tech News
← Back to articles

PSA: Don’t trust that Chrome update popup — it could be malware

read original more articles
Why This Matters

This article highlights a growing security threat where malicious browser extensions generate fake update pop-ups, tricking users into downloading malware. The issue affects multiple Chromium-based browsers and underscores the importance of scrutinizing browser extensions to prevent malware infections. Recognizing and removing suspicious extensions is crucial for maintaining browser security and protecting personal data.

Key Takeaways

Edgar Cervantes / Android Authority

TL;DR Persistent pop-ups urging you to update Chrome may actually be malware pushed by compromised browser extensions.

The issue affects Chromium-based browsers like Chrome, Brave, and Opera, attempting to trick users into running potentially malicious scripts.

Identifying and removing suspicious or newly acquired extensions is currently the primary way to stop the pop-ups.

We all have our favorite Chrome extensions that make daily web browsing effortless, whether it’s a quick screen snip tool, a right-click unlocker, or a simple tab manager. But what happens when one of those trusty add-ons quietly turns against you? Over the past few days, an increasing number of web users have fallen victim to a frustratingly convincing browser scam that tricks people into downloading harmful malware disguised as routine system updates.

The issue manifests as an aggressive pop-up claiming a “Critical Update Required” or “Update available” to keep using your browser. If you click to proceed, instead of a standard browser update, it downloads a suspicious .vbs or .exe script directly to your machine.

As one frustrated user reported on Reddit, traditional antivirus software like Malwarebytes often fails to flag anything during full system scans. That is because the browser itself isn’t infected; rather, an extension you installed is dynamically fetching malicious scripts from an external server to trigger the fake notification inside your browser session.

What makes this attack vector particularly insidious is that it isn’t isolated to Google Chrome. Users on alternative Chromium platforms like Brave and Opera are reporting identical pop-ups asking them to update Chrome, a dead giveaway of a rogue script at play. In a thread on the Brave Community forum from earlier this year, affected users traced these occurrences back to a compromised utility known as QuickLens – Search Screen with Google Lens, which was eventually pulled from the Web Store.

In more recent reports, users pinpointed extensions such as “Enable Right Click & Copy Smart Unlock + OCR” and various utility helpers as the culprits behind the fake update prompts. The extension is still live on the Chrome Web Store, has 70,000 downloads, and a 4.7/5 rating, meaning most users love it.

Hillary Keverenge / Android Authority

... continue reading