CRX aminer
Extension icon

Avast Online Security & Privacy (BETA)

Version 22.11.178 View in Chrome Web Store

Last scanned: 2 days ago | force re-scan

Extension Details

Developer: https://www.avast.com/
Rating: 4.4 ★ (57 ratings)
Size: 1.87MiB
Last Updated: April 27, 2023
Users: 60,000
Developer Info: Gen Digital60 E Rio Salado Pkwy Tempe, AZ 85281-9124 US

Context-Aware Verdict

HIGH
Risk Level
Trust Factors:
- Avast is a well-known cybersecurity company, which adds some credibility to the extension.
- The extension has a relatively high number of users (60,000) and a good rating (4.4/5), suggesting that many users find it useful and trustworthy.
Concerns:
- The extension requests a broad range of permissions, including the ability to access all websites, store data locally, access browser tabs, track web navigation, intercept and modify web requests, and inject scripts into any website.
- The combination of webRequest and webRequestBlocking permissions is particularly concerning, as it could potentially be used to modify sensitive web traffic or steal data.
- The use of the older Manifest Version 2 means that the extension has fewer security restrictions than the newer Manifest V3.
Recommendations:
- Exercise caution when using this extension, as the broad permissions it requests could potentially be exploited for malicious purposes.
- Consider running the extension in a separate Chrome profile or a sandboxed environment to limit its access to sensitive data and minimize potential risks.
- Monitor the extension's behavior and check for any suspicious activities, such as unexpected web requests or modifications to website content.
- Keep an eye on updates from Avast and the extension's reviews, as any security issues or concerns may be addressed in future versions.
- If you have concerns about the extension's behavior or potential risks, consider disabling or uninstalling it and exploring alternative security solutions.

Security Analysis

CRITICAL
Overall Risk
Based on 8 total findings, ranked without considering overall context, including 6 high-risk and 2 medium-risk findings.
HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Dangerous Permission Combination: webRequest + webRequestBlocking
This extension can intercept, modify, and block web requests in real-time. This combination could be used to modify sensitive web traffic or steal data.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequestBlocking
This extension has the webRequestBlocking permission. Can block and modify web requests in real-time. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.