Even then. I'm not sure why extension config-data isn't transparently replicated between hosts, but it's a really noticeable problem when you have an extension installed that's as complex as XKit or RES. Even for uBlock, you have to copy-and-paste your whitelist rules between hosts, rather than having them just follow you around.
AVG managed to. [1]
> When a user installs AVG AntiVirus, a Chrome extension called "AVG Web TuneUp" with extension id chfdnecihphmhljaaejmgoiahnihplgn is force-installed. I can see from the webstore statistics it has nearly 9 million active Chrome users.
> This extension adds numerous JavaScript API's to chrome, apparently so that they can hijack search settings and the new tab page. The installation process is quite complicated so that they can bypass the chrome malware checks, which specifically tries to stop abuse of the extension API.
[1] https://code.google.com/p/google-security-research/issues/de...
Addendum: In checking, I confirmed AntiVir and Avast both trick users into installing Chrome as I have screenshots of it (as well as Java, Adobe Flash, etc). I recall AVG doing it as well but don't have the associated screenshots.
The key insight is that Chrome itself is programmed to have quite-limited permissions—it not only heavily sandboxes itself, but it also does what it can to avoid requesting any powers from the OS that could be used to do damage in the first place, if one were to break out of the sandbox. (This also has the side-benefit that Chrome doesn't need any of those "scary" UAC elevation prompts during installation, which probably helps their funnel to an extent.)
This means that Chrome actually doesn't have any of the permissions required to weed out the GPOs responsible for feeding it malware extensions. Even if the Chrome process wanted to reach out and blow them away, it couldn't. So they created this separate program, that does do "scary" UAC-elevation things, to help out.
(What they could have done is package this program into the Windows Chrome install, make it headless, and make a button in the Chrome settings that would spawn it and then interact with it over IPC, displaying the UI on the Chrome side. They could have, further, made it just-in-time download the component—as, IIRC, Firefox does with its Hello component—which would have eliminated any install-time size overhead to this approach.)
Also Chrome installs on the user $HOME, thus avoiding some of the security mechanisms that would be place, if Google would do it properly.
Also Macs don't get viruses as frequently. I'm not saying they're less susceptible but it does happen less often.
(see: any recent COTS Windows PC, especially Lenovo)
Seems like you are comparing Oranges n Apples.
Except if your BIOS has WPBT which provides for installing such bloatware. Like Lenovo has done.
https://www.techdirt.com/articles/20150812/11395231925/lenov...
>No one stops you from installing clean Windows OS without bloatware.
Ah sure, that's every average PC user's first step after unboxing their shiny new laptop. Wipe it with DBAN and do a fresh install.
Just kidding, it's pretty obviously not. Most people don't even know what wiping a computer entails, or how to do it, or that it would actually get rid of the bloat. These things seem simple to us but most people don't understand the first thing about computers.
No one stops you from buying a Mac because you're sick of dealing with bloatware either. Just sayin'.
>Can you tell me one single product in Apple which is sold by other than Apple.
No clue what you're trying to say there.
The problem on windows is the insidious third-party apps that inject their extensions into chrome and re-create them when you try to remove them so the only way to actually get rid of them is a specialized tool.