If you're seeing pop-ups in Chrome pushing you to download an update in order to continue browsing or avoid losing access to your data, you may be a target for malware. As Android Authority reports, compromised browser extensions appear to be distributing malicious scripts disguised as "critical" security updates. Hackers are using malicious extensions to spread fake security updatesSome Google Chrome users have noticed aggressive pop-ups alerting them to required updates and prompting them to download the latest version of the browser. One version states that "access to websites is temporarily blocked" until the update is installed. The other is even more urgent, stating that Chrome will stop working after a certain date and require a "complete reinstallation," in which users may lose access to bookmarks, history, and saved passwords. If you click "Update Chrome," it'll download a suspicious .vbs or .exe script to your device. The issue seems to be traceable to a handful of extensions, which are fetching malicious scripts and serving fake prompts inside the browser. In Chrome, one such add-on is “Enable Right Click & Copy Smart Unlock + OCR," which has a "Featured" tag and 70,000 downloads (though other utility tools may be culprits as well). Users on Brave and Opera, both Chromium browsers, have reported identical pop-ups. For the former, the compromised extension, called "QuickLens – Search Screen with Google Lens," was removed from the Web Store. While some malicious add-ons do find their way onto the Chrome Web Store, it's not uncommon for threat actors to weaponize otherwise benign extensions after gaining platform approval and user trust. In campaigns identified across Chrome, Microsoft Edge, and Firefox, hackers have built extensions posing as crypto wallet and productivity apps, let them operate legitimately to rack up downloads and reviews, and then pushed updates that turned them into malware. This is an effective strategy because malicious extensions can evade detection by antivirus software and system scans. The browser itself isn't compromised—rather, the add-on is pulling malicious scripts from a remote server, and the threat isn't picked up until you actually download and execute them on your device. Don't download security updates from pop-upsIf you start seeing pop-ups for critical security updates in your browser, don't click on them, and don't copy or install anything from them. The alerts in this campaign have fairly convincing Chrome branding and elements like a copyright and links to a privacy policy and terms of service, but beware the sense of urgency. You can check whether your browser actually needs to be updated in the settings menu (on Chrome, click the three vertical dots or go to Settings > About Chrome). You should also regularly check the extensions you've added to your browser and delete any that aren't essential. Click the extensions icon > Manage Extensions to see what's active and review permissions granted. If you're still getting sketchy pop-ups, try removing utility apps to see if you can identify the culprit.