CRX aminer
Extension icon

McAfee® WebAdvisor

Version 8.1.0.9066 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Rating: 4.6 ★ (15.3K ratings)
Users: 148,000,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors: McAfee is a well-established cybersecurity company with a strong reputation in the industry. The extension has an impressive 148 million users and a solid 4.6-star rating from over 15,000 reviews, indicating widespread adoption and general user satisfaction. The extension's purpose as a web security advisor justifies many of its extensive permissions, as it needs broad access to monitor and protect users from malicious websites and downloads.
Concerns: While the permissions are extensive, they align with the extension's security function. The webRequest permission allows real-time threat detection, downloads permission enables scanning of downloaded files, and broad host permissions are necessary for comprehensive web protection. The 'wasm-unsafe-eval' CSP directive is concerning but may be required for advanced threat detection algorithms. The main risk comes from the sheer scope of access this extension has to your browsing data and activities.
Recommendations: Given McAfee's reputation and the extension's legitimate security purpose, the risk is mitigated compared to unknown developers with similar permissions. However, users should ensure they trust McAfee with their browsing data, as this extension can monitor all web activity. Consider whether you need this level of protection versus built-in browser security features. If you have concerns about data privacy, review McAfee's privacy policy carefully. The extension appears to function as intended for a security tool from a reputable company.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.