ARTICLE AD BOX
You are browsing the web when a warning suddenly takes over the page. It says your browser needs a "Critical Update" before you can continue. It looks like Chrome. The message feels urgent. So, clicking Update may seem like the safest thing you can do. That is exactly what makes this fake Chrome update scam so convincing.
Recent reports linked aggressive fake browser update warnings to a Chrome extension called Enable Right Click & Copy - Smart Unlock + OCR. The extension was originally developed as a legitimate tool for restoring right-click and copying features on websites that block them. However, security researchers at Socket now say the extension was later acquired by a threat actor and updated with malicious functionality. It had around 70,000 users when that malicious functionality appeared, although researchers caution that this does not mean every user received the malicious version. The extension was delisted from the Chrome Web Store on Aug. 14 after being flagged as potentially malicious.
FAKE WINDOWS UPDATE INSTALLS HIDDEN MALWARE
The bigger lesson goes beyond one extension. Something you installed months ago and trusted every day can change after an update. Here's how this fake Chrome update scam works, how to spot the warning signs and what you can do to protect your browser and computer.
Missed CyberGuy LIVE? Watch the Protect Your Money replay
Our free CyberGuy LIVE class, Protect Your Money From Today’s Biggest Threats, has ended, but you can still watch the full replay and download our financial protection checklist. Kurt "CyberGuy" Knutsson walks you through five simple ways to help defend yourself against AI scams, fraud, identity theft and financial hacks. You’ll learn how to set up bank alerts, strengthen your account logins, protect your phone number, freeze your credit and help secure your retirement savings against unauthorized transfers. No technical experience is needed.
Get the free replay and checklist now at CyberGuyLive.com.
The warning can appear while you are visiting an otherwise normal website. You may see language such as "Critical Update Required" or "Update available." The alert then pushes you to download something before you continue browsing.
However, Chrome normally handles its updates through the browser itself. Google says Chrome usually updates automatically in the background. You can also check manually by opening Chrome and going to More > Help > About Google Chrome.
A webpage asking you to download a .vbs script or an unfamiliar .exe file to update Chrome should immediately raise your suspicion. Google specifically advises users to avoid suspicious pop-ups asking them to install updates. Instead, Google recommends going directly to the program or its official website.
Here is the part that can catch careful people off guard. You may have installed an extension when it had thousands of users, strong reviews and no obvious signs of trouble. You use it for months. Then the extension changes.
Google confirmed to CyberGuy that it looked into Enable Right Click & Copy - Smart Unlock + OCR. "We've investigated the extension and taken action to protect our users," a Google spokesperson told CyberGuy.
New research published by Socket on Aug. 27 shows the threat went beyond fake update warnings. Researchers linked the extension to a larger campaign involving 19 Chrome and Edge extensions capable of delivering malicious payloads. Those capabilities included credential theft, cryptocurrency wallet draining, injected phishing pages and fake browser update lures. Socket says some of the extensions began as legitimate products before being acquired and weaponized by the threat actor.
We have seen that pattern before. Earlier this year, researchers found that QuickLens - Search Screen with Google Lens changed ownership before a malicious update arrived. The extension had previously earned a Featured badge from Google. Researchers later found malicious functionality capable of injecting code, displaying fake Google update prompts and targeting sensitive information. Google removed QuickLens from the Chrome Web Store.
CyberGuy has also reported on trusted browser extensions that later became spyware. One campaign affected 4.3 million users after extensions that began as useful tools eventually received malicious updates. That history changes how I look at browser extensions. A great rating tells you what people thought when they reviewed an extension. It cannot guarantee what a future update will do.
This recent extension case had another detail I think everyone should notice. Enable Right Click & Copy - Smart Unlock + OCR still had an average rating near 4.7 stars as reports of the fake update warnings appeared. That can happen because thousands of earlier positive ratings remain part of the overall score.
Meanwhile, recent reviews can begin filling with warnings. In this case, August reviews accused the extension of injecting fake Chrome update alerts. Several users said removing or disabling it stopped the prompts.
So, before installing an extension, look beyond the overall star rating. Read the newest reviews as well. CyberGuy previously covered another browser-extension scam involving a fake ad blocker. That extension created computer problems and then tried to convince users to run dangerous commands to fix them.
One Reddit user who encountered the recent fake update warnings said a full scan found nothing. The user later traced the pop-ups to the Right Click extension.
A clean scan should never convince you that a suspicious browser warning is safe. The extension itself may be creating or injecting what you see inside the browser. Meanwhile, a downloaded malicious file may pose a separate threat if you open or execute it.
Google's Safe Browsing system checks installed extensions and downloads against known threats. Chrome can also disable extensions that Google identifies as malicious. Still, newly emerging threats can create a window where users encounter trouble before defenses catch up. That is why your own reaction to a suspicious prompt remains important.
FAKE CAPTCHA SCAM CAN HACK YOUR COMPUTER
Seeing a Chrome-branded warning inside another browser gives you a pretty good clue that something is wrong.
Users of Chromium-based browsers including Brave and Opera have reported similar fake Chrome update prompts. Users connected those warnings with suspicious browser extensions rather than genuine browser updates.
That makes sense because Chromium-based browsers can support many of the same types of browser extensions. If Opera suddenly tells you that Google Chrome desperately needs an update, do not follow the prompt.
You never need to trust a random webpage to tell you whether Chrome needs updating. On your computer:
Open Chrome > click the three-dot menu > Help > About Google Chrome.
Chrome will check for available updates on that page. If an update has already been downloaded, you may see an option to relaunch Chrome. If you do not see Relaunch, Google says you are running the latest available version. That simple check can take much of the guesswork out of a scary update warning.
Look carefully at what you have installed. Google lets you turn an extension off temporarily or remove it completely. You can also open an extension's details and review whether it can read or change data on every website you visit.
If you have Enable Right Click & Copy - Smart Unlock + OCR installed, I would remove it even if you never clicked or opened one of the suspicious downloads. Researchers found malicious capabilities that went beyond the fake update prompts. Then restart Chrome, run a full security scan and change passwords for sensitive accounts you used while the extension was installed from another trusted device.
If you have several unfamiliar extensions, disable them and re-enable only the ones you recognize and still need. For more help identifying warning signs, CyberGuy has a full guide explaining how to tell if your browser has been hijacked.
A few smart habits can lower your chances of turning a convincing pop-up into a serious security problem.
If a webpage tells you to download an update, close the warning. Then go directly to Chrome > Help > About Google Chrome. Google also warns people to use caution when websites claim you need to download software because your device has a virus.
Strong antivirus protection adds another defense between a bad download and your computer. Look for antivirus software that provides real-time protection, rather than relying only on occasional manual scans. Real-time protection can monitor files as they arrive and look for suspicious behavior before malware gets a chance to spread.
Keep the antivirus software updated as well. New threats appear constantly, so outdated security software can leave gaps. If you clicked a fake update or accidentally ran a suspicious file, perform a full system scan. Follow the antivirus program's instructions if it detects malware. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.
Take a minute every few months to see what you have installed.
In Chrome on your computer:
Pay particular attention to extensions that can read and change your data on all websites you visit. Google classifies access to data across all websites as a higher-risk permission because an extension may be able to read, request or modify information on pages you visit. If an extension suddenly asks for broader permissions or you no longer remember why you installed it, I would remove it.
FAKE PARTY INVITATION SCAM CAN HIJACK YOUR COMPUTER
Do not rely only on the overall rating. Scroll down and look at what people have written recently. A long history of five-star reviews can hide a sudden change that users discovered only days ago. If recent reviews suddenly mention pop-ups, malware or unexpected redirects, choose another extension.
For additional protection, open: Chrome > Settings > Privacy and security > Security > Enhanced protection. Google says Enhanced Protection can warn you about potentially dangerous websites, downloads and extensions, including threats that Chrome has not previously identified. It also provides deeper checks on suspicious downloads.
If you clicked a fake update and it downloaded a .vbs, .exe or another unfamiliar file, do not open it. Delete it. Then empty your Recycle Bin or Trash and run a full security scan. Chrome may also block files it considers dangerous, suspicious or unverified. Treat those warnings seriously rather than overriding them to get the download through.
A data removal service cannot remove malware from your computer. However, it can reduce another piece of the scammer's advantage: the amount of personal information about you that sits online. Data brokers can collect details such as contact information, previous addresses and other identifying information. Scammers can use exposed data to make follow-up phishing attempts feel much more believable. For example, a scammer who already knows your name, phone number and where you live has more material to personalize a fake security alert. Data removal services work by sending removal requests to data brokers and other sites that publish personal information. They can also continue checking whether your information reappears. Reducing that digital footprint will never stop every scam. However, giving criminals less information to work with can make targeted attacks harder to personalize. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.
If you actually executed the suspicious file, treat the computer as potentially compromised.
If you removed a suspicious extension and the warning still appears, continue narrowing down the cause.
What bothers me most about this fake Chrome update scam is how little suspicious behavior it requires from the person being targeted. You could have downloaded a useful extension from the official Chrome Web Store. It could have worked exactly as promised. It could even have thousands of happy users. Then something changes behind the scenes. That means we need to stop treating browser extensions as install-once-and-forget-about-it utilities. Every extension gets a level of access to your browser. The fewer you keep around, the smaller that exposure becomes. I would also make one rule nonnegotiable: Never update Chrome because a webpage tells you to download a file. Open Chrome's settings and check the update yourself. That extra 20 seconds could save you from turning a convincing fake warning into a much bigger security headache.
How much do you trust a browser extension's star rating or download count when deciding whether it is safe to install? Let us know by writing to us at CyberGuy.com.
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.

1 hour ago
1







English (US) ·