CRX aminer
Extension icon

Chrome Remote Desktop

Version 2.1 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: Google Ireland, Ltd.
Rating: 3.1 ★ (2.9K ratings)
Users: 36,000,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

Chrome Remote Desktop is developed by Google Ireland, Ltd., which provides significant credibility and trustworthiness. With 36 million users, it's one of the most widely adopted remote desktop solutions. However, the relatively low rating of 3.1 out of 5 from nearly 3,000 reviews suggests user experience issues that warrant attention.

Concerns:

The primary concern is the downloads permission, which allows the extension to download files and access download history. While this permission may be necessary for file transfer functionality in remote desktop sessions, it creates potential privacy and security risks. The nativeMessaging permission, though expected for remote desktop functionality, enables communication with native applications on the host system, which could be exploited if the extension were compromised.

The combination of these permissions in a remote access tool creates a significant attack surface, as malicious actors could potentially use the extension to download malicious files or access sensitive download history.

Recommendations:

Given Google's reputation and the extension's widespread use, the medium risk level is primarily due to the inherent nature of remote desktop software rather than malicious intent. Users should ensure they only use this extension on trusted networks and devices. For enhanced security, consider running it in a separate Chrome profile when accessing sensitive systems. Regularly review your download history and monitor for any unexpected file downloads when using the extension.

Findings

HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.