Ui.Vision appears to be a legitimate automation and testing tool with 200,000 users and a 3.9-star rating. The developer "ui.vision" suggests this is the official extension from the UI.Vision team, which creates browser automation software. However, the moderate rating (3.9/5) from 238 reviews indicates mixed user experiences.
The extension's permission set is extremely broad and powerful, far exceeding what most users would expect. The debugger permission is particularly concerning as it allows manipulation of other extensions. The combination of clipboard access, cookie manipulation, proxy control, and web request interception creates a perfect storm for data theft. The unsafe WebAssembly execution policy could hide malicious code, and the broad host permissions with content script injection across all websites means this extension has unprecedented access to your entire browsing experience.
While these permissions may be legitimate for an automation tool, they create significant attack surface if the extension is compromised or malicious.
Run this extension in a completely separate Chrome profile dedicated solely to automation tasks. Never use this profile for personal browsing, banking, or accessing sensitive accounts. Consider using alternative automation tools with more limited permissions if possible. If you must use this extension, regularly audit what data it has access to and monitor for unusual network activity. Keep the extension updated and remove it immediately if you notice suspicious behavior.
| https://medium.com/@martin_hotell/improved-redux-type-safety-with-typescript-2-8-2c11a8062575 | https://github.com/facebook/regenerator/blob/main/LICENSE | |
| https://stackoverflow.com/questions/6081483/maximum-size-of-a-canvas-element/11585939#11585939 | https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Interact_with_the_clipboard#Browser-specific_considerations_2 | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1425829 | https://github.com/teamdocs/sidebar_uiv/issues/106 | |
| https://goto.ui.vision/x/idehelp?help=xclick_updatecheck&xversion= | https://goto.ui.vision/x/idehelp?help=xclick_download | |
| https://goto.ui.vision/x/idehelp?help=xclick | https://goto.ui.vision/x/idehelp?help=xdesktop_updatecheck&xversion= | |
| https://goto.ui.vision/x/idehelp?help=xdesktop_download | https://goto.ui.vision/x/idehelp?help=xdesktop | |
| https://goto.ui.vision/x/idehelp?help=xmodule-ocr_updatecheck&xversion= | https://goto.ui.vision/x/idehelp?help=xmodule-ocr_download | |
| https://goto.ui.vision/x/idehelp?help=xmodule-ocr | http://eligrey.com | |
| https://github.com/eligrey/FileSaver.js/blob/master/LICENSE.md | http://purl.eligrey.com/github/FileSaver.js/blob/master/FileSaver.js | |
| https://bugzilla.mozilla.org/show_bug.cgi?format=default&id=1420419 | http://www.w3.org/1999/xhtml | |
| https://developer.apple.com/library/safari/documentation/Tools/Conceptual/SafariExtensionGuide/WorkingwithWindowsandTabs/WorkingwithWindowsandTabs.html | https://www.gamepix.com/play/tic-tac-toe-html5 | |
| https://www.theonlinecalculator.com/ | https://ui.vision/contact | |
| https://forum.ui.vision/ | https://docs.google.com/forms/d/1cbI5dMRs0-t_IwNzPm6T3lAG_nPgsnJZEA-FEYVARxg/ | |
| https://ui.vision/rpa/docs/selenium-ide/form-filling | https://ui.vision/demo/webtest/dragdrop/ | |
| https://ui.vision/demo/filedownload | https://ui.vision/demo/executescript | |
| https://ui.vision/demo/webtest/frames/ | https://ui.vision/blog/ | |
| https://ui.vision/demo/executeScript | https://ui.vision/demo/iframes | |
| https://ui.vision/demo/waitforelementvisible | https://ui.vision/demo/webtest/implicitwaiting/ | |
| https://ui.vision/demo/csvsave | http://download.ui.vision/demo/pdf-test.pdf | |
| https://ocr.space | https://forum.ui.vision/t/string-search-startswith-and-includes/10081/3 | |
| https://ui.vision/demo/draw | https://ui.vision/demo/tabs | |
| https://ui.vision | https://ui.vision/ | |
| https://ui.vision/demo/xtype | https://ui.vision/x/desktop-automation#ocr | |
| https://ui.vision/rpa/x/desktop-automation/screen-scraping | https://docs.google.com/forms/d/e/1FAIpQLScGWVjexH2FNzJqPACzuzBLlTWMJHgLUHjxehtU-2cJxtu6VQ/viewform | |
| https://blog.prototypr.io/align-svg-icons-to-text-and-say-goodbye-to-font-icons-d44b3d7b26b4 | https://github.com/ant-design/ant-design/blob/master/components/date-picker/locale/example.json | |
| https://stackoverflow.com/a/32749533/1755633 | http://www.w3.org/2000/svg | |
| http://www.w3.org/1999/xlink | https://goto.ui.vision/x/idehelp?help=relative_clicks | |
| https://drafts.csswg.org/css-values-3/#urls | https://lodash.com/ | |
| https://jquery.org/ | https://lodash.com/license | |
| http://underscorejs.org/LICENSE | http://ecma-international.org/ecma-262/7.0/#sec-object.prototype.tostring | |
| https://css-tricks.com/debouncing-throttling-explained-examples/ | http://www.ecma-international.org/ecma-262/7.0/#sec-ecmascript-language-types | |
| http://ixti.net/development/javascript/2011/11/11/base64-encodedecode-of-utf8-in-browser-with-js.html | https://tools.ietf.org/html/rfc2315 | |
| http://www.requirejs.org/docs/api.html | https://github.com/amdjs/amdjs-api/wiki/AMD | |
| http://www.json.org/JSON_checker/utf8_decode.c | https://goto.ui.vision/x/idehelp?help=k_update | |
| https://goto.ui.vision/x/idehelp?help=k_welcome | https://goto.ui.vision/x/idehelp?help=k_why | |
| https://goto.ui.vision/x/idehelp?help=k_xupgradepro | https://goto.ui.vision/x/idehelp?help=k_xupgrade_contactsupport | |
| https://api.ocr.space/parse/image | https://apipro1.ocr.space/parse/image | |
| https://apipro2.ocr.space/parse/image | https://license1.ocr.space/api/status | |
| https://github.com/teamdocs/selenium-ide-chrome-light-2017/issues/884#issuecomment-1088739538 | https://developer.chrome.com/docs/extensions/whatsnew/#m100-native-msg-lifetime | |
| https://goto.ui.vision/x/idehelp?help=xfileaccess_updatecheck&xversion= | https://goto.ui.vision/x/idehelp?help=xfileaccess_download |
{ "name": "__MSG_name__", "icons": { "128": "logo128.png" }, "action": { "default_icon": { "38": "logo38.png" } }, "version": "9.6.0", "background": { "service_worker": "background.js" }, "short_name": "__MSG_short_name__", "side_panel": { "default_path": "sidepanel.html" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "__MSG_description__", "permissions": [ "bookmarks", "clipboardRead", "clipboardWrite", "cookies", "debugger", "downloads", "downloads.ui", "notifications", "storage", "tabs", "activeTab", "proxy", "nativeMessaging", "contextMenus", "webRequest", "webRequestAuthProvider", "sidePanel", "scripting" ], "options_page": "options.html", "default_locale": "en", "content_scripts": [ { "js": [ "content_script.js" ], "run_at": "document_start", "matches": [ "<all_urls>" ], "all_frames": true, "match_about_blank": true } ], "offline_enabled": true, "host_permissions": [ "<all_urls>" ], "manifest_version": 3, "content_security_policy": { "extension_pages": "script-src 'self' 'wasm-unsafe-eval';" }, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "content_script.js", "inject.js", "logo.png" ], "extension_ids": [] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.