Description of the issue:
Extensions seem to be autoupdating, which would allow a compromised extension to issue a malicious update that would be automatically downloaded, potentially violating privacy/security.
How can this issue be reproduced?
- Install any extension;
- Do nothing;
- Wait for extension to autoupdate.
Expected result:
Doing nothing should not result in extension being automatically updated. Or at least there should be a way to disable that and a button for manually updating extensions when updates are available.
Brave Version( checkAbout Brave
):
Version 1.47.186 Chromium: 109.0.5414.119 (Official Build) (64-bit)
Additional Information:
frequently, updates are inferior to what is already installed