A troubling issue has emerged surrounding the popular Immersive Translation browser plugin, prompting swift action from its development team. On August 9, the plugin’s official team made a significant announcement regarding the temporary removal of a key functionality that had raised serious questions about user data protection.
What Happened: User Data Exposure Risk
Community members began reporting that the bilingual webpage sharing feature—a convenient tool that allowed users to distribute translated web content—had become a potential security vulnerability. Several users disclosed that they had inadvertently distributed pages containing sensitive personal information while leveraging this feature, and critically, failed to promptly remove these shared links from their personal accounts. The situation escalated when some users reported that their wallet private keys appeared to have been compromised, suggesting that the plugin’s permissions may have extended beyond their intended scope.
Further investigation highlighted concerns about the “webpage snapshot” functionality, which observers suggested contained structural vulnerabilities that could potentially expose user data.
Official Response and Clarification
In response to mounting concerns, the Immersive Translation team moved decisively by halting the bilingual webpage sharing function effective immediately. The official statement emphasized that “no leakage of translated content or backend user data has occurred” and clarified that “externally accessible links are generated only when users actively initiate the bilingual webpage sharing process.”
The team committed to maintaining the feature offline until comprehensive privacy safeguards can be implemented and thoroughly tested.
Important Caveat for Users
BlockBeats notes that no major cybersecurity organization has issued formal warnings about this incident at this time. The platform recommends users approach the situation thoughtfully and remain vigilant about protecting their digital assets. Further developments in this matter will be monitored closely.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Privacy Concerns Prompt Immersive Translation Plugin to Disable Content Sharing Feature
A troubling issue has emerged surrounding the popular Immersive Translation browser plugin, prompting swift action from its development team. On August 9, the plugin’s official team made a significant announcement regarding the temporary removal of a key functionality that had raised serious questions about user data protection.
What Happened: User Data Exposure Risk
Community members began reporting that the bilingual webpage sharing feature—a convenient tool that allowed users to distribute translated web content—had become a potential security vulnerability. Several users disclosed that they had inadvertently distributed pages containing sensitive personal information while leveraging this feature, and critically, failed to promptly remove these shared links from their personal accounts. The situation escalated when some users reported that their wallet private keys appeared to have been compromised, suggesting that the plugin’s permissions may have extended beyond their intended scope.
Further investigation highlighted concerns about the “webpage snapshot” functionality, which observers suggested contained structural vulnerabilities that could potentially expose user data.
Official Response and Clarification
In response to mounting concerns, the Immersive Translation team moved decisively by halting the bilingual webpage sharing function effective immediately. The official statement emphasized that “no leakage of translated content or backend user data has occurred” and clarified that “externally accessible links are generated only when users actively initiate the bilingual webpage sharing process.”
The team committed to maintaining the feature offline until comprehensive privacy safeguards can be implemented and thoroughly tested.
Important Caveat for Users
BlockBeats notes that no major cybersecurity organization has issued formal warnings about this incident at this time. The platform recommends users approach the situation thoughtfully and remain vigilant about protecting their digital assets. Further developments in this matter will be monitored closely.