Skip to content
Skip to content

Independent e-magazine

the OUTSPOKEN digest

Chrome Deleted the Last of the Old Extensions Yesterday, and the Ad Blockers Are the Point

31 August was the date the remaining Manifest V2 extensions came out of the Chrome Web Store. They stopped running more than a year ago. What changed yesterday is that you can no longer get them back.

Outspoken Digest Technology Desk

Tuesday, September 1, 2026/3 min read

The Google sign outside the company's Charleston Road offices in Mountain View, California, photographed in 2022
Photo: Dietmar Rabich via Wikimedia Commons (CC BY-SA 4.0)

Google set 31 August as the date it would remove the remaining Manifest V2 extensions from the Chrome Web Store, and that date has now passed.

Most people will not notice, because the part that affected them happened in July 2025, when Chrome 138 removed the toggle that let users re-enable those extensions and they stopped running on stable Chrome for everyone. Yesterday was the last step of a long retirement: the listings are gone.

What actually changed

Recoverability.

If you are running an older Chrome build with a legacy extension still installed, it keeps working and stops receiving updates. What you cannot do any more is get it again. Reset the browser, buy a new machine, reinstall Chrome, and the extension is not there to reinstall.

That is a smaller change than the headlines suggest and a more permanent one. A capability that is merely disabled can be re-enabled. A listing that has been deleted is gone from the only distribution channel most users have.

Why Manifest V3 was contentious

Because of one specific capability, not the whole design.

The old extension model let an extension inspect network requests as they happened and decide, in its own code, what to do with each one. That is a large amount of power to hand a third party, and Google's stated case for removing it is genuine: an extension with that access can read everything you do, and thousands of them have.

The replacement asks extensions to declare rules in advance that the browser then enforces. The browser does the blocking; the extension does not see the traffic. That is better for privacy against a malicious extension and worse for any blocker whose method depends on reacting to what it sees.

Both of those are true at once, which is why the argument never resolved. The honest summary is that the change improves the security model and reduces what the most capable blockers can do, and that Google sells advertising, so it never got the benefit of the doubt on which of those it was optimising for.

Where that leaves blocking

Rule based blockers work on current Chrome and will continue to. Content still gets blocked, filter lists still update within the limits the new model sets, and for most people the practical experience is close to what it was.

What is gone is the class of blocking that needed to inspect and rewrite requests dynamically. If you were running one of those and it stopped a year ago, this is the moment the option to go back closes.

The reasonable responses are: use a Manifest V3 blocker and accept the ceiling, block at the network level instead so the browser is not involved at all, or use a browser that kept the old model. That last one is a real answer rather than a protest, and it is the one being quietly taken by people who care about this most.

The pattern underneath

This is the second time in a week that the browser's role as the place where trust is decided has been the story.

Extensions have always been the softest part of a browser's security. They ask for broad permissions at install time, users grant them without reading, and the extension can be sold to somebody else afterwards without the user ever being told. Manifest V3 narrows what a compromised or bought extension can do, and that is worth something real.

It does not touch the other route in. Malware on the machine itself takes the session and the permissions regardless of the extension model, which is what happened to a set of Claude accounts and which we set out in the piece on stolen session cookies. Hardening the extension platform while the operating system underneath is compromised is a fence with the gate open.

And the browser is becoming more powerful, not less, as agents move into it. We looked at what that does to the permission question in the arrival of agents in the browser, where something is being given the ability to act on your behalf on every page you have logged into.

What to do today

Nothing urgent, and one thing worth five minutes.

Open your extensions page and look at what is installed. Remove anything you do not recognise or no longer use, because every one of them is an ongoing grant of access to a party you have long since stopped thinking about. The retirement of an old extension format is a decent prompt for the audit almost nobody does.

Published in The Outspoken Digest

Editorial desk

Outspoken Digest Technology Desk

Software, hardware, artificial intelligence and what they change for everyone else.

Newsletter

The Digest, in your inbox

One edition, sent when it is ready. No noise, and your address is never passed on.

We send a confirmation first. One click to leave, always.

Share this story

the OUTSPOKEN digest

Beyond boundaries. Independent stories on technology, culture, and the trends shaping how we live.