Security News > 2020 > January > Google Halts Publishing of Paid Chrome Extensions Due to Fraud

After observing an increase in the number of fraudulent transactions, Google over the weekend announced that it halted the publishing of paid items to the Chrome Web Store.
"Earlier this month the Chrome Web Store team detected a significant increase in the number of fraudulent transactions involving paid Chrome extensions that aim to exploit users. Due to the scale of this abuse, we have temporarily disabled publishing paid items," Simeon Vincent, extensions developer advocate at Google, explains.
Some developers are already seeing their extensions rejected even following minor fixes.
Some of the developers replying to Vincent's announcement complained about Google not informing them about this measure earlier.
"While it's unknown what is happening at Google and its actions, it must be a serious issue. Speculation from my experience would be one of fraud, where the criminals have infiltrated the Chrome store and inserted malicious code to steal personal identifiable information, along with credit card information," James McQuiggan, security awareness advocate at KnowBe4, told SecurityWeek in an emailed comment.
News URL
Related news
- Google Drops Cookie Prompt in Chrome, Adds IP Protection to Incognito (source)
- Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android (source)
- Google Chrome to use on-device AI to detect tech support scams (source)
- Google Chrome to block admin-level browser launches for better security (source)
- Google fixes high severity Chrome flaw with public exploit (source)
- Google Chrome's Built-in Manager Lets Users Update Breached Passwords with One Click (source)
- Google Chrome to distrust Chunghwa Telecom, Netlock certificates in August (source)
- New Chrome Zero-Day Actively Exploited; Google Issues Emergency Out-of-Band Patch (source)
- Google Chrome to Distrust Two Certificate Authorities Over Compliance and Conduct Issues (source)
- Google patches new Chrome zero-day bug exploited in attacks (source)