Why privacy matters
Development often touches sensitive environments. VibeHeader stores Profiles, headers, filters, and preferences locally. Share payloads stay after # in the URL, which browsers do not include in the request for the /s page. The complete link still contains the setup, so it should be treated as sensitive.
These concerns stopped being hypothetical in July 2026, when Google flagged ModHeader v7.0.18 as malware and Microsoft pulled it from the Edge store, after researchers reported it quietly collected the domains users visited. If you had that version installed, see the ModHeader malware cleanup & self-check guide to remove it, wipe its leftover data, and rotate any secrets you pasted into it.
References
- ModHeader privacy statement — modheader.com/privacy
- Extension monetization risks overview — Krebs on Security