CRX aminer
Extension icon

ZoomInfo Chrome Extension

Version 11.39.0 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Developer: ZoomInfo Technologies Inc.
Rating: 3.9 ★ (257 ratings)
Users: 400,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

ZoomInfo is a legitimate B2B contact database company with a substantial user base of 400,000 downloads. The extension maintains a reasonable 3.9-star rating from 257 reviews, indicating general user satisfaction. The company is well-established in the business intelligence sector, which adds credibility to the extension's purpose.

Concerns:

The extension's broad permissions are concerning given its business intelligence nature. The combination of tabs permission, universal host permissions, and content script injection across all websites creates significant privacy risks. While ZoomInfo legitimately needs to access websites to gather business contact information, these permissions could theoretically allow comprehensive browsing surveillance and data collection beyond stated purposes. The access to Google's new tab page suggests potential tracking of search behavior.

The extension essentially has the technical capability to monitor all web activity, read sensitive information from any website, and store this data locally. For a contact intelligence tool, this level of access raises questions about data collection scope and user privacy.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to business research activities. Review ZoomInfo's privacy policy carefully to understand data collection practices. Regularly audit what data the extension has access to through Chrome's extension management settings. If you only use ZoomInfo occasionally, consider disabling the extension when not actively needed for prospecting work.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://www.google.com/_/chrome/newtab*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.