Jump to content

SimilarWeb: Difference between revisions

From Consumer Rights Wiki
new company page on similarweb (nyse: smwb) covering the corporate background, the may 2021 ipo, the may 2026 ceo succession announcement, and the three consumer-rights incidents tied to the stylish and similarweb-branded browser extensions (2018 heaton takedown, 2026 arnott return + wall of shame, separately-confirmed exfiltration of the similarweb extension).
 
Line 12: Line 12:
'''SimilarWeb''' (legally Similarweb Ltd.) is an Israeli digital-market-intelligence company that owns two Chrome Web Store extensions independently documented exfiltrating their users' browsing data: [[Stylish (Chrome extension)|Stylish]], with roughly 2 million users, & a [[SimilarWeb (browser extension)|self-branded SimilarWeb traffic-rank extension]] with roughly 1 million users.<ref name="aibp-wos">{{Cite web |url=https://amibeingpwned.com/ai-chat-scraper-wall-of-shame/ |title=The AI Chat Scraping Extension Wall of Shame |last=Arnott |first=James |publisher=amibeingpwned |date=2026-05-11 |access-date=2026-05-30}}</ref><ref name="bc-2017">{{Cite web |url=https://www.bleepingcomputer.com/news/software/2-million-users-impacted-by-new-data-collection-policy-in-stylish-browser-add-on/ |title=2 Million Users Impacted by New Data Collection Policy in Stylish Browser Add-On |last=Cimpanu |first=Catalin |publisher=BleepingComputer |date=2017-01-04 |access-date=2026-05-30}}</ref> The company trades on the New York Stock Exchange under the ticker SMWB after a May 12, 2021 initial public offering.<ref name="smwb-ipo">{{Cite web |url=https://www.similarweb.com/corp/success-stories/similarweb-announces-closing-of-ipo/ |title=Similarweb Announces Closing of Initial Public Offering |publisher=Similarweb |date=2021-05-14 |access-date=2026-05-30}}</ref> Both extensions were classified as ''"Confirmed"'' AI-chat scrapers in security researcher James Arnott's May 11, 2026 audit, which documented chat content from ChatGPT, Claude, & Character.AI leaving users' browsers in network traffic.<ref name="aibp-wos" />
'''SimilarWeb''' (legally Similarweb Ltd.) is an Israeli digital-market-intelligence company that owns two Chrome Web Store extensions independently documented exfiltrating their users' browsing data: [[Stylish (Chrome extension)|Stylish]], with roughly 2 million users, & a [[SimilarWeb (browser extension)|self-branded SimilarWeb traffic-rank extension]] with roughly 1 million users.<ref name="aibp-wos">{{Cite web |url=https://amibeingpwned.com/ai-chat-scraper-wall-of-shame/ |title=The AI Chat Scraping Extension Wall of Shame |last=Arnott |first=James |publisher=amibeingpwned |date=2026-05-11 |access-date=2026-05-30}}</ref><ref name="bc-2017">{{Cite web |url=https://www.bleepingcomputer.com/news/software/2-million-users-impacted-by-new-data-collection-policy-in-stylish-browser-add-on/ |title=2 Million Users Impacted by New Data Collection Policy in Stylish Browser Add-On |last=Cimpanu |first=Catalin |publisher=BleepingComputer |date=2017-01-04 |access-date=2026-05-30}}</ref> The company trades on the New York Stock Exchange under the ticker SMWB after a May 12, 2021 initial public offering.<ref name="smwb-ipo">{{Cite web |url=https://www.similarweb.com/corp/success-stories/similarweb-announces-closing-of-ipo/ |title=Similarweb Announces Closing of Initial Public Offering |publisher=Similarweb |date=2021-05-14 |access-date=2026-05-30}}</ref> Both extensions were classified as ''"Confirmed"'' AI-chat scrapers in security researcher James Arnott's May 11, 2026 audit, which documented chat content from ChatGPT, Claude, & Character.AI leaving users' browsers in network traffic.<ref name="aibp-wos" />


== Background ==
==Background==


SimilarWeb was founded in 2007 by Or Offer & is headquartered in Givatayim, Israel. Its core business sells web & app traffic intelligence to brands, investors, & publishers; a portion of the underlying panel data is sourced from a network of browser extensions, mobile applications, & user panels that the company owns or partners with.<ref name="bc-2017" />
SimilarWeb was founded in 2007 by Or Offer & is headquartered in Givatayim, Israel. Its core business sells web & app traffic intelligence to brands, investors, & publishers; a portion of the underlying panel data is sourced from a network of browser extensions, mobile applications, & user panels that the company owns or partners with.<ref name="bc-2017" />
Line 18: Line 18:
The company priced its IPO on May 12, 2021, selling 8,000,000 ordinary shares on the New York Stock Exchange under ticker SMWB, with J.P. Morgan, Citigroup, Barclays, & Jefferies serving as joint book-running managers.<ref name="smwb-ipo" /> On May 13, 2026, the board announced that founder & CEO Or Offer would step down by mid-2027 & opened a formal succession process.<ref name="calcalist-succession">{{Cite web |url=https://www.calcalistech.com/ctechnews/article/h1nullf1mx |title=Similarweb begins CEO succession process as founder Or Offer plans to step down |publisher=Calcalist Tech |date=2026-05-13 |access-date=2026-05-30}}</ref>
The company priced its IPO on May 12, 2021, selling 8,000,000 ordinary shares on the New York Stock Exchange under ticker SMWB, with J.P. Morgan, Citigroup, Barclays, & Jefferies serving as joint book-running managers.<ref name="smwb-ipo" /> On May 13, 2026, the board announced that founder & CEO Or Offer would step down by mid-2027 & opened a formal succession process.<ref name="calcalist-succession">{{Cite web |url=https://www.calcalistech.com/ctechnews/article/h1nullf1mx |title=Similarweb begins CEO succession process as founder Or Offer plans to step down |publisher=Calcalist Tech |date=2026-05-13 |access-date=2026-05-30}}</ref>


== Browser extensions ==
==Browser extensions==


In January 2017, the then-owner of [[Stylish (Chrome extension)|Stylish]] announced a data-collection partnership tying the user-styles extension into SimilarWeb's analytics panel. At the time of the partnership, Stylish had approximately 2 million users across Chrome, Firefox, Opera, & Safari.<ref name="bc-2017" /> SimilarWeb itself was the named owner of the extension by the time Robert Heaton's July 2018 disclosure prompted Chrome & Firefox to remove it.<ref name="heaton-2018" /> The Chrome Web Store listing as of May 2026 still shows roughly 2 million users.<ref name="aibp-wos" />
In January 2017, the then-owner of [[Stylish (Chrome extension)|Stylish]] announced a data-collection partnership tying the user-styles extension into SimilarWeb's analytics panel. At the time of the partnership, Stylish had approximately 2 million users across Chrome, Firefox, Opera, & Safari.<ref name="bc-2017" /> SimilarWeb itself was the named owner of the extension by the time Robert Heaton's July 2018 disclosure prompted Chrome & Firefox to remove it.<ref name="heaton-2018" /> The Chrome Web Store listing as of May 2026 still shows roughly 2 million users.<ref name="aibp-wos" />
Line 24: Line 24:
The company also distributes a self-branded [[SimilarWeb (browser extension)|SimilarWeb traffic-rank extension]] with roughly 1 million Chrome Web Store users, which serves both as a consumer-facing site-comparison tool & as a primary data-collection channel feeding SimilarWeb's panel.<ref name="aibp-wos" /> Neither extension's Chrome Web Store listing discloses, on the install page itself, the AI-chat exfiltration documented by independent researchers in 2025 & 2026.<ref name="aibp-wos" />
The company also distributes a self-branded [[SimilarWeb (browser extension)|SimilarWeb traffic-rank extension]] with roughly 1 million Chrome Web Store users, which serves both as a consumer-facing site-comparison tool & as a primary data-collection channel feeding SimilarWeb's panel.<ref name="aibp-wos" /> Neither extension's Chrome Web Store listing discloses, on the install page itself, the AI-chat exfiltration documented by independent researchers in 2025 & 2026.<ref name="aibp-wos" />


== Incidents ==
==Incidents==


=== 2018 Stylish data-exfiltration disclosure ===
===2018 Stylish data-exfiltration disclosure===


On July 2, 2018, software engineer Robert Heaton published a technical writeup showing that the SimilarWeb-owned Stylish extension was sending every URL its users visited, together with a persistent unique identifier, to <code>api.userstyles.org</code>. Heaton noted that for users who had also created a userstyles.org account, the identifier could be linked to a login cookie, tying browsing histories to real-world identities.<ref name="heaton-2018">{{Cite web |url=https://robertheaton.com/2018/07/02/stylish-browser-extension-steals-your-internet-history/ |title=Stylish browser extension steals all your internet history |last=Heaton |first=Robert |date=2018-07-02 |access-date=2026-05-30}}</ref> Within two days of publication, both Google & Mozilla removed Stylish from the Chrome Web Store & the Firefox add-ons store; The Register & BleepingComputer independently confirmed the removals.<ref name="heaton-2018" /><ref name="register-2018">{{Cite web |url=https://www.theregister.com/2018/07/05/stylish_browser_extension_dropped/ |title=Stylish browser extension dropped by Mozilla, Google over snooping |publisher=The Register |date=2018-07-05 |access-date=2026-05-30}}</ref> A modified version was back in the Firefox add-on store by August 16, 2018 behind an opt-in startup screen.<ref name="heaton-back">{{Cite web |url=https://robertheaton.com/2018/08/16/stylish-is-back-and-you-still-shouldnt-use-it/ |title="Stylish" is back, and you still shouldn't use it |last=Heaton |first=Robert |date=2018-08-16 |access-date=2026-05-30}}</ref> See [[Stylish (Chrome extension)]] for the full technical record.
On July 2, 2018, software engineer Robert Heaton published a technical writeup showing that the SimilarWeb-owned Stylish extension was sending every URL its users visited, together with a persistent unique identifier, to <code>api.userstyles.org</code>. Heaton noted that for users who had also created a userstyles.org account, the identifier could be linked to a login cookie, tying browsing histories to real-world identities.<ref name="heaton-2018">{{Cite web |url=https://robertheaton.com/2018/07/02/stylish-browser-extension-steals-your-internet-history/ |title=Stylish browser extension steals all your internet history |last=Heaton |first=Robert |date=2018-07-02 |access-date=2026-05-30}}</ref> Within two days of publication, both Google & Mozilla removed Stylish from the Chrome Web Store & the Firefox add-ons store; The Register & BleepingComputer independently confirmed the removals.<ref name="heaton-2018" /><ref name="register-2018">{{Cite web |url=https://www.theregister.com/2018/07/05/stylish_browser_extension_dropped/ |title=Stylish browser extension dropped by Mozilla, Google over snooping |publisher=The Register |date=2018-07-05 |access-date=2026-05-30}}</ref> A modified version was back in the Firefox add-on store by August 16, 2018 behind an opt-in startup screen.<ref name="heaton-back">{{Cite web |url=https://robertheaton.com/2018/08/16/stylish-is-back-and-you-still-shouldnt-use-it/ |title="Stylish" is back, and you still shouldn't use it |last=Heaton |first=Robert |date=2018-08-16 |access-date=2026-05-30}}</ref> See [[Stylish (Chrome extension)]] for the full technical record.
<!-- INCIDENT_SCORE: 70 | major historical incident: confirmed exfiltration of every URL from approximately 2M users, prompted Chrome & Firefox takedowns within two days -->
<!-- INCIDENT_SCORE: 70 | major historical incident: confirmed exfiltration of every URL from approximately 2M users, prompted Chrome & Firefox takedowns within two days -->


=== 2026 Stylish return & Wall of Shame ===
===2026 Stylish return & Wall of Shame===


On February 26, 2026, security researcher James Arnott of amibeingpwned documented that Stylish, by then carrying Chrome Web Store ''"Featured"'' & ''"Verified Publisher"'' badges, was again exfiltrating every URL its users visited, along with conversation content from AI chat sites including ChatGPT, Claude, & Character.AI. Arnott reverse-engineered a five-stage obfuscation pipeline: URL encoding, double base64 of JSON, columnar transposition, AES-256-CBC encryption with a symmetric key hardcoded in the extension source, & a final base64 wrap.<ref name="aibp-stylish-back">{{Cite web |url=https://amibeingpwned.com/posts/stylish-is-back/ |title=Stylish is Back, Back again! |last=Arnott |first=James |publisher=amibeingpwned |date=2026-02-26 |access-date=2026-05-30}}</ref> On May 11, 2026, Arnott published an AI Chat Scraper Wall of Shame that classified Stylish as ''"Confirmed"'' with ''"Extensive"'' obfuscation, citing direct observation of chat content leaving the browser in network traffic.<ref name="aibp-wos" /> Full technical detail at [[Stylish (Chrome extension)]] & [[Browser extension AI chat exfiltration]].
On February 26, 2026, security researcher James Arnott of amibeingpwned documented that Stylish, by then carrying Chrome Web Store ''"Featured"'' & ''"Verified Publisher"'' badges, was again exfiltrating every URL its users visited, along with conversation content from AI chat sites including ChatGPT, Claude, & Character.AI. Arnott reverse-engineered a five-stage obfuscation pipeline: URL encoding, double base64 of JSON, columnar transposition, AES-256-CBC encryption with a symmetric key hardcoded in the extension source, & a final base64 wrap.<ref name="aibp-stylish-back">{{Cite web |url=https://amibeingpwned.com/posts/stylish-is-back/ |title=Stylish is Back, Back again! |last=Arnott |first=James |publisher=amibeingpwned |date=2026-02-26 |access-date=2026-05-30}}</ref> On May 11, 2026, Arnott published an AI Chat Scraper Wall of Shame that classified Stylish as ''"Confirmed"'' with ''"Extensive"'' obfuscation, citing direct observation of chat content leaving the browser in network traffic.<ref name="aibp-wos" /> Full technical detail at [[Stylish (Chrome extension)]] & [[Browser extension AI chat exfiltration]].
<!-- INCIDENT_SCORE: 85 | actively confirmed; verbatim cipher chain documented; AI chat content from ChatGPT/Claude/Character.AI exfiltrated; Featured + Verified Publisher badges -->
<!-- INCIDENT_SCORE: 85 | actively confirmed; verbatim cipher chain documented; AI chat content from ChatGPT/Claude/Character.AI exfiltrated; Featured + Verified Publisher badges -->


=== SimilarWeb-branded extension confirmed exfiltration ===
===SimilarWeb-branded extension confirmed exfiltration===


Arnott's May 11, 2026 Wall of Shame separately classified the self-branded SimilarWeb extension (≈1 million users, carrying a Chrome Web Store ''"Verified"'' badge) as ''"Confirmed"'' for exfiltrating AI chat content & full URLs. Arnott noted that the data collection occurs ''"even when you're not using the extension"'' & that, unlike Stylish, the SimilarWeb-branded extension applies no obfuscation to the exfiltrated payload.<ref name="aibp-wos" /> See [[Browser extension AI chat exfiltration]] for cross-extension analysis & detection methodology.
Arnott's May 11, 2026 Wall of Shame separately classified the self-branded SimilarWeb extension (≈1 million users, carrying a Chrome Web Store ''"Verified"'' badge) as ''"Confirmed"'' for exfiltrating AI chat content & full URLs. Arnott noted that the data collection occurs ''"even when you're not using the extension"'' & that, unlike Stylish, the SimilarWeb-branded extension applies no obfuscation to the exfiltrated payload.<ref name="aibp-wos" /> See [[Browser extension AI chat exfiltration]] for cross-extension analysis & detection methodology. Arnott made a video<ref>{{Cite web |last=AmIBeingPwned |title=Similarweb - URL, OpenAI JWT and AI chat exfiltration demo |url=https://www.youtube.com/watch?v=-c5Jewuqrqw |url-status=live |website=YouTube}}</ref> documenting the behavior.
<!-- INCIDENT_SCORE: 60 | Confirmed exfiltration of URLs + AI chat content from ~1M users; no obfuscation; classified Confirmed in May 2026 Wall of Shame -->
<!-- INCIDENT_SCORE: 60 | Confirmed exfiltration of URLs + AI chat content from ~1M users; no obfuscation; classified Confirmed in May 2026 Wall of Shame -->


== Products ==
==Products==


* [[Stylish (Chrome extension)]]: user-styles extension with SimilarWeb data-collection partnership announced January 2017
*[[Stylish (Chrome extension)]]: user-styles extension with SimilarWeb data-collection partnership announced January 2017
* [[SimilarWeb (browser extension)]]: self-branded traffic-rank extension
*[[SimilarWeb (browser extension)]]: self-branded traffic-rank extension


== See also ==
==See also==


* [[Stylish (Chrome extension)]]
*[[Stylish (Chrome extension)]]
* [[SimilarWeb (browser extension)]]
*[[SimilarWeb (browser extension)]]
* [[Browser extension AI chat exfiltration]]
*[[Browser extension AI chat exfiltration]]
* [[Stylus]]
*[[Stylus]]


== References ==
==References==


{{reflist}}
{{reflist}}

Revision as of 23:11, 31 May 2026

SimilarWeb
[[File:|200px]]
Basic information
Founded 2007
Legal Structure Public
Industry Digital market intelligence,Web analytics,Browser extensions
Also known as Similarweb,Similarweb Ltd.,SMWB
Official website https://www.similarweb.com/

SimilarWeb (legally Similarweb Ltd.) is an Israeli digital-market-intelligence company that owns two Chrome Web Store extensions independently documented exfiltrating their users' browsing data: Stylish, with roughly 2 million users, & a self-branded SimilarWeb traffic-rank extension with roughly 1 million users.[1][2] The company trades on the New York Stock Exchange under the ticker SMWB after a May 12, 2021 initial public offering.[3] Both extensions were classified as "Confirmed" AI-chat scrapers in security researcher James Arnott's May 11, 2026 audit, which documented chat content from ChatGPT, Claude, & Character.AI leaving users' browsers in network traffic.[1]

Background

SimilarWeb was founded in 2007 by Or Offer & is headquartered in Givatayim, Israel. Its core business sells web & app traffic intelligence to brands, investors, & publishers; a portion of the underlying panel data is sourced from a network of browser extensions, mobile applications, & user panels that the company owns or partners with.[2]

The company priced its IPO on May 12, 2021, selling 8,000,000 ordinary shares on the New York Stock Exchange under ticker SMWB, with J.P. Morgan, Citigroup, Barclays, & Jefferies serving as joint book-running managers.[3] On May 13, 2026, the board announced that founder & CEO Or Offer would step down by mid-2027 & opened a formal succession process.[4]

Browser extensions

In January 2017, the then-owner of Stylish announced a data-collection partnership tying the user-styles extension into SimilarWeb's analytics panel. At the time of the partnership, Stylish had approximately 2 million users across Chrome, Firefox, Opera, & Safari.[2] SimilarWeb itself was the named owner of the extension by the time Robert Heaton's July 2018 disclosure prompted Chrome & Firefox to remove it.[5] The Chrome Web Store listing as of May 2026 still shows roughly 2 million users.[1]

The company also distributes a self-branded SimilarWeb traffic-rank extension with roughly 1 million Chrome Web Store users, which serves both as a consumer-facing site-comparison tool & as a primary data-collection channel feeding SimilarWeb's panel.[1] Neither extension's Chrome Web Store listing discloses, on the install page itself, the AI-chat exfiltration documented by independent researchers in 2025 & 2026.[1]

Incidents

2018 Stylish data-exfiltration disclosure

On July 2, 2018, software engineer Robert Heaton published a technical writeup showing that the SimilarWeb-owned Stylish extension was sending every URL its users visited, together with a persistent unique identifier, to api.userstyles.org. Heaton noted that for users who had also created a userstyles.org account, the identifier could be linked to a login cookie, tying browsing histories to real-world identities.[5] Within two days of publication, both Google & Mozilla removed Stylish from the Chrome Web Store & the Firefox add-ons store; The Register & BleepingComputer independently confirmed the removals.[5][6] A modified version was back in the Firefox add-on store by August 16, 2018 behind an opt-in startup screen.[7] See Stylish (Chrome extension) for the full technical record.

2026 Stylish return & Wall of Shame

On February 26, 2026, security researcher James Arnott of amibeingpwned documented that Stylish, by then carrying Chrome Web Store "Featured" & "Verified Publisher" badges, was again exfiltrating every URL its users visited, along with conversation content from AI chat sites including ChatGPT, Claude, & Character.AI. Arnott reverse-engineered a five-stage obfuscation pipeline: URL encoding, double base64 of JSON, columnar transposition, AES-256-CBC encryption with a symmetric key hardcoded in the extension source, & a final base64 wrap.[8] On May 11, 2026, Arnott published an AI Chat Scraper Wall of Shame that classified Stylish as "Confirmed" with "Extensive" obfuscation, citing direct observation of chat content leaving the browser in network traffic.[1] Full technical detail at Stylish (Chrome extension) & Browser extension AI chat exfiltration.

SimilarWeb-branded extension confirmed exfiltration

Arnott's May 11, 2026 Wall of Shame separately classified the self-branded SimilarWeb extension (≈1 million users, carrying a Chrome Web Store "Verified" badge) as "Confirmed" for exfiltrating AI chat content & full URLs. Arnott noted that the data collection occurs "even when you're not using the extension" & that, unlike Stylish, the SimilarWeb-branded extension applies no obfuscation to the exfiltrated payload.[1] See Browser extension AI chat exfiltration for cross-extension analysis & detection methodology. Arnott made a video[9] documenting the behavior.

Products

See also

References

  1. 1.0 1.1 1.2 1.3 1.4 1.5 1.6 Arnott, James (2026-05-11). "The AI Chat Scraping Extension Wall of Shame". amibeingpwned. Retrieved 2026-05-30.
  2. 2.0 2.1 2.2 Cimpanu, Catalin (2017-01-04). "2 Million Users Impacted by New Data Collection Policy in Stylish Browser Add-On". BleepingComputer. Retrieved 2026-05-30.
  3. 3.0 3.1 "Similarweb Announces Closing of Initial Public Offering". Similarweb. 2021-05-14. Retrieved 2026-05-30.
  4. "Similarweb begins CEO succession process as founder Or Offer plans to step down". Calcalist Tech. 2026-05-13. Retrieved 2026-05-30.
  5. 5.0 5.1 5.2 Heaton, Robert (2018-07-02). "Stylish browser extension steals all your internet history". Retrieved 2026-05-30.
  6. "Stylish browser extension dropped by Mozilla, Google over snooping". The Register. 2018-07-05. Retrieved 2026-05-30.
  7. Heaton, Robert (2018-08-16). ""Stylish" is back, and you still shouldn't use it". Retrieved 2026-05-30.
  8. Arnott, James (2026-02-26). "Stylish is Back, Back again!". amibeingpwned. Retrieved 2026-05-30.
  9. AmIBeingPwned. "Similarweb - URL, OpenAI JWT and AI chat exfiltration demo". YouTube.{{cite web}}: CS1 maint: url-status (link)