Drooid Logo
Back to story perspectives

Full Breakdown

LinkedIn's BrowserGate: Covert Scanning and Data Collection Practices

4/5/2026, 11:57:33 PM

Overview of BrowserGate

LinkedIn has come under scrutiny for its practice of scanning users' browsers for over 6,000 installed Chrome extensions and collecting detailed device telemetry. This operation, referred to as "BrowserGate," involves a hidden JavaScript routine that runs every time a user accesses the platform through a Chrome-based browser. The script collects 48 hardware and software characteristics, creating a unique fingerprint that persists even after cookies are cleared. This data is then encrypted and transmitted to LinkedIn's servers, where it is attached to every API request made during the session.

Technical Details of the Scanning Process

The scanning process, described by LinkedIn as “Spectroscopy,” operates by sending up to 6,222 simultaneous requests to check for specific browser extensions. The presence of these extensions can indicate users' interests and behaviors, including the use of competing sales tools like Apollo, Lusha, and ZoomInfo. The scale of this operation has significantly increased, with the number of scanned extensions rising from 38 in 2017 to 6,167 by February 2026.

Legal and Regulatory Context

LinkedIn's practices occur within a broader context of regulatory scrutiny in Europe. In October 2024, the Irish Data Protection Commission fined LinkedIn €310 million for processing personal data without a valid legal basis. The current investigation raises questions about whether scanning for browser extensions constitutes processing of sensitive personal data, as defined by the General Data Protection Regulation (GDPR). The lack of disclosure regarding this practice in LinkedIn's privacy policy further complicates its legal standing.

Official Statements and Responses

In response to the allegations, LinkedIn has stated that the scanning is a security measure aimed at identifying extensions that scrape data or violate its terms of service. A spokesperson emphasized that the company does not use the collected data to infer sensitive information about users. However, critics argue that the scale and nature of the data collection constitute covert surveillance of users' browsing behaviors.

Criticism and Opposition

Critics of LinkedIn's practices highlight the ethical implications of such extensive data collection without user consent. The BrowserGate report indicates that the scanning includes tools related to neurodivergent conditions, religious practices, and job-hunting activities, which are classified as sensitive personal data in the EU. This raises concerns about user privacy and the potential for misuse of the collected data.

Conflicting Reports and Gaps

While LinkedIn disputes the characterizations made in the BrowserGate report, the technical findings regarding the scanning behavior have been independently verified by BleepingComputer. The framing of the report is contested, particularly due to the connection between Fairlinked e. V., the organization behind the report, and Teamfluence, a company whose extension was restricted by LinkedIn.

Conclusion: Implications for Users

With over one billion registered users, the implications of LinkedIn's scanning practices are significant. The lack of user-facing settings to prevent this scanning, combined with the absence of an opt-out option, raises questions about user awareness and consent. As regulatory frameworks evolve to address such practices, the future of LinkedIn's data collection methods remains uncertain. The BrowserGate investigation serves as a critical case study in the ongoing dialogue about privacy, data collection, and user rights in the digital age.