Every time you visit LinkedIn in a Chrome-based browser, a hidden JavaScript silently scans your browser for more than 6,000 installed extensions, collects 48 hardware and software characteristics of your device, encrypts the result, and attaches it to every API request you make during your session. This practice, which the researchers have dubbed “BrowserGate,” is not mentioned in LinkedIn’s privacy policy.
See also: PXA Stealer malware campaign from Vietnam exploits LinkedIn

LinkedIn says this is a security measure, while critics describe it as covert monitoring of the browsing behavior of a billion users on an industrial scale.
There’s a routine that runs on your computer every time you open LinkedIn. You can’t see it, you weren’t informed about it, and it’s not described in the company’s privacy policy. According to research published in early April 2026 by Fairlinked eV, a European association of commercial users of LinkedIn, the platform inserts a 2.7-megabyte JavaScript package into its website that silently scans visitors’ browsers for the presence of more than 6,000 specific Chrome extensions, composes a detailed fingerprint of their device, encrypts it, and transmits the result to LinkedIn’s servers, where it’s linked to every subsequent action taken during the session.
What does the script do?
LinkedIn calls its scanning system “Spectroscopy.” When a user loads the LinkedIn website, the script executes up to 6,222 simultaneous requests, each of which examines a specific browser extension, attempting to access files associated with the extension’s ID. The presence or absence of a file in the response indicates whether the extension is installed. The entire operation runs silently in the background, without any visible notification or update of any kind.
See also: North Koreans pose as IT professionals on LinkedIn to infiltrate companies

Beyond the extensions, the script collects 48 different characteristics of the user's device: number of CPU cores, available memory, screen resolution, time zone, language settings, battery status, audio information, and storage capacity, among others. Individually, these characteristics are not noticeable. Combined, they form a device fingerprint specific enough to identify a user even after clearing cookies.
Once composed, the data is serialized to JSON and encrypted using an RSA public key, LinkedIn’s internal identifier for the key is “apfcDfPK,” before being transmitted to telemetry points such as li/track and /platform-telemetry/li/apfcDf. The fingerprint is then permanently inserted as an HTTP header in every API request made during the session, meaning LinkedIn receives it with every search, every profile view, every message sent.
What is he looking for?
The question of which extensions LinkedIn scans makes the monitoring more sensitive than simple fraud detection would require. According to the BrowserGate report, LinkedIn’s list includes more than 200 products that directly compete with its own sales tools, including Apollo, Lusha , and ZoomInfo. Because LinkedIn knows the employer of every registered user, systematically scanning for the presence of a competitor tool gives the platform visibility into which companies are evaluating or developing competing products.
See also: Hackers use LinkedIn messages to spread RAT malware

The list also reportedly includes tools related to neurodifferentiated conditions, religious practice, political interests, and work-related activities.
