I recently installed a browser extension called GeoSpoof to change my location on a university attendance website, along with its mobile app so I could use Safari to access the site. A few days later, I noticed suspicious activity across several accounts. Someone accessed my LinkedIn account from Safari at the spoofed location, then from another location in my country and later from India. They added their own email address and two-factor authentication, activated premium features, and connected the account to an organization. I eventually recovered it through support.
After that, I found an unfamiliar login to my Instagram account and removed the device. My mother's Microsoft account was also flagged for a suspicious login, and I had her Apple ID saved in Chrome. My old Facebook account was locked because of suspicious activity as well.
The extension's permission notice said it could read and modify pages, view browsing history, and access sensitive information such as passwords, phone numbers, and payment details. I have already changed important passwords, but I'm unsure whether this was caused by stolen passwords, hijacked sessions, malware, or something else. What should I do next to secure my devices and accounts?
3 Answers
The extension author’s explanation may indicate that the software was not designed to collect form inputs, but open-source code and stated permissions still don’t rule out a compromised device, stolen session cookies, password reuse, phishing, or another extension. Focus on containment: secure the primary email and Apple or Microsoft account first, then recover the other accounts, replace recovery details, enable two-factor authentication, and monitor login alerts and payment activity for several weeks.
Treat this as a possible device and session compromise rather than just a few isolated password breaches. Remove the extension and its mobile app, revoke active sessions from every affected account, and review recovery email addresses, phone numbers, two-factor authentication methods, connected apps, payment methods, and account rules for anything unfamiliar. Change passwords again from a device you trust, and make sure every account has a unique password. If possible, use an authenticator app or hardware security key instead of SMS for important accounts.
A browser extension with permission to read and modify every webpage can potentially access information displayed in logged-in sessions, even if it doesn’t directly send passwords to its developer. The permission by itself doesn’t prove that this extension caused the attacks, though. The safest approach is to remove it, sign out of all sessions, clear browser data, update the operating system and browsers, and run a reputable security scan. A factory reset is reasonable if you cannot establish that the device is clean.

I couldn’t identify the exact cause, so I factory-reset the device and am working through the account security checks from a clean device.