CRX aminer
Extension icon

Read on reMarkable

Version 1.2.6 View in Chrome Web Store

Last scanned: about 8 hours ago

Extension Details

Rating: 3.5 ★ (114 ratings)
Users: 400,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a substantial user base of 400,000 users, indicating reasonable adoption and community trust. However, the rating of 3.5 out of 5 stars with only 114 reviews suggests mixed user satisfaction or limited engagement. The extension appears to serve a legitimate purpose - integrating with reMarkable devices for document reading. The manifest version 3 compliance shows the developer is keeping up with modern security standards.

Concerns:

The primary concern is the broad host permissions flagged as high-risk, though in this case it's specifically scoped to remarkable.com domains rather than all websites. The printerProvider permission, while not flagged in findings, is unusual and could potentially be misused for data exfiltration through print job manipulation. The combination of activeTab, scripting, and storage permissions creates a capability set that could access and store content from any active tab the user interacts with through the extension.

Recommendations:

This extension presents moderate risk due to its permission set, but the risk is somewhat mitigated by its specific integration purpose with reMarkable services. Users should monitor what content they send through this extension and avoid using it on sensitive pages. Consider running it in a separate Chrome profile if you frequently handle confidential documents. Regularly review the extension's behavior and remove it if you notice unexpected activity or if you no longer use reMarkable devices.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.