Version 5.5.186 View in Chrome Web Store
Loom is a well-established company with a legitimate screen recording service. The extension has 8 million users and a strong 4.6-star rating from over 10,000 reviews, indicating widespread adoption and user satisfaction. The developer is the official loom.com domain, adding credibility to the extension's authenticity.
While Loom's functionality justifies many permissions, several raise privacy concerns. The cookies permission combined with webRequest and webNavigation allows comprehensive tracking of browsing behavior. The broad host permissions (<all_urls>) and content script injection capabilities mean Loom can access sensitive data on any website you visit. The system.memory and system.cpu permissions, while useful for performance optimization, provide deep system access. The unsafe WebAssembly execution policy creates potential security vulnerabilities.
The extensive list of specific content scripts targeting popular business platforms (Gmail, Slack, Notion, etc.) suggests deep integration but also means Loom can access sensitive business communications and documents.
Given Loom's legitimate business purpose and strong reputation, the risk is manageable for most users. However, privacy-conscious users should consider running it in a separate Chrome profile to isolate its broad access. Review your Loom privacy settings and consider disabling the extension when not actively recording. For highly sensitive work environments, evaluate whether the convenience justifies the extensive data access permissions.
| http://www.w3.org/2000/svg | https://github.com/emscripten-core/emscripten/wiki/Linking | |
| https://cdn.loom.com/tflite/v2/ | https://cdn.loom.com/tflite/ | |
| https://support.atlassian.com/confluence-cloud/docs/insert-links-and-anchors/#Smart-Links-from-Jira-and-other-products | http://feross.org | |
| https://feross.org | https://github.com/focus-trap/focus-trap/blob/master/LICENSE | |
| https://github.com/focus-trap/tabbable/blob/master/LICENSE | https://feross.org/opensource | |
| https://github.com/babel/babel/blob/main/packages/babel-helpers/LICENSE | https://lodash.com/ | |
| https://openjsf.org/ | https://lodash.com/license | |
| http://underscorejs.org/LICENSE | http://jaywcjlove.github.io/hotkeys | |
| http://underscorejs.org | https://github.com/uuidjs/uuid#getrandomvalues-not-supported | |
| https://slack.com/target_uri | https://slack.com/team_domain | |
| https://slack.com/team_id | https://slack.com/team_name | |
| https://slack.com/user_id | https://support.loom.com/hc/en-us/articles/360002187698-Getting-started-with-the-Chrome-Extension | |
| https://support.loom.com/hc/en-us/articles/360002207917-Getting-started-with-the-Desktop-App | https://chrome.google.com/webstore/detail/loom-video-recorder-scree/liecbddmkiiihnedobmlmillhodjkdmb | |
| https://loom.com | https://stage.loom.com | |
| https://loomlocal.com:4444 | https://www.loom.com | |
| http://fb.me/use-check-prop-types | https://api.atlassian-us-gov-mod.com/flags | |
| https://api.stg.atlassian-us-gov-mod.com/flags | https://api.dev.atlassian.com/flags | |
| https://api.stg.atlassian.com/flags | https://api.atlassian.com/flags | |
| https://atlassian-statsig-proxy-archetype.atl-paas.%s.atl-ic.net | https://xp.atlassian.com/v1/rgstr | |
| https://www.googleapis.com/auth/userinfo.email | https://www.googleapis.com/auth/userinfo.profile | |
| https://www.googleapis.com/auth/calendar.readonly | https://www.googleapis.com/auth/calendar.events | |
| https://www.googleapis.com/auth/meetings.conference.media.readonly | https://www.googleapis.com/auth/meetings.space.readonly | |
| https://www.googleapis.com/auth/admin.directory.user.readonly | https://www.googleapis.com/oauth2/v3/tokeninfo | |
| https://www.googleapis.com/auth/gmail.send | https://cloudflare-dns.com/dns-query | |
| https://as.atlassian-us-gov-mod.com/api | https://as.staging.atl-paas-us-gov-mod.net/api | |
| https://as.atlassian.com/api | https://as.staging.atl-paas.net/api | |
| https://api.segment.io | https://reactjs.org/docs/error-decoder.html?invariant= | |
| http://www.w3.org/1999/xlink | http://www.w3.org/XML/1998/namespace | |
| http://www.w3.org/1998/Math/MathML | http://www.w3.org/1999/xhtml | |
| https://npms.io/search?q=ponyfill. | https://statsigapi.net/v1/sdk_exception | |
| https://teams.cloud.microsoft | https://teams.microsoft.com | |
| https://docs.statsig.com/client/javascript-sdk/#typed-getters | https://docs.datadoghq.com/real_user_monitoring/browser/troubleshooting/#customer-data-exceeds-the-recommended-3kib-warning | |
| https://www.datadoghq-browser-agent.com | https://www.datad0g-browser-agent.com | |
| https://d3uc069fcn7uxw.cloudfront.net | https://d20xtzwzcl0ceb.cloudfront.net | |
| http://www.example.com | https://github.com/nodeca/pako | |
| https://prodregistryv2.org/v1 | https://featureassets.org/v1 | |
| https://api.statsigcdn.com/v1 | https://lens.loom.dev/guides/development-best-practices/the-risk-of-modifying-components-with-custom-styles. | |
| https://cdn.loom.com/assets/lens | https://bit.ly/3cXEKWf | |
| https://redux.js.org/Errors?code= | https://463bb92641e54586a41d8c96ac9fe8e5@o398470.ingest.sentry.io/4504323419602944 | |
| https://cdn.loom.com/assets/camfort/windows_xp.jpeg | https://www.loom.com/metrics/graphql |
{ "name": "Loom – Screen Recorder & Screen Capture", "icons": { "16": "images/icon_16.png", "32": "images/icon_32.png", "48": "images/icon_64.png", "128": "images/icon_128.png" }, "action": { "default_icon": { "16": "images/icon_16.png", "32": "images/icon_32.png", "48": "images/icon_64.png", "128": "images/icon_128.png" }, "default_popup": "html/popup.html" }, "version": "5.5.186", "commands": { "_execute_action": { "suggested_key": { "mac": "Alt+Shift+L", "linux": "Alt+Shift+L", "windows": "Alt+Shift+L", "chromeos": "Alt+Shift+L" } }, "cancel-recording": { "description": "Cancel a Recording", "suggested_key": { "mac": "Alt+Shift+C", "linux": "Alt+Shift+C", "windows": "Alt+Shift+C", "chromeos": "Alt+Shift+C" } }, "restart-recording": { "description": "Restart a Recording", "suggested_key": { "mac": "Alt+Shift+R", "linux": "Alt+Shift+R", "windows": "Alt+Shift+R", "chromeos": "Alt+Shift+R" } }, "toggle-pause-recording": { "description": "Pause/Resume a Recording", "suggested_key": { "mac": "Alt+Shift+P", "linux": "Alt+Shift+P", "windows": "Alt+Shift+S", "chromeos": "Alt+Shift+P" } } }, "background": { "service_worker": "js/sw.js" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "Record your screen and camera with one click. Share that content in an instant with a link.", "permissions": [ "system.memory", "activeTab", "alarms", "contextMenus", "cookies", "desktopCapture", "scripting", "storage", "system.cpu", "system.display", "tabCapture", "webNavigation", "webRequest" ], "version_name": "5.5.186", "content_scripts": [ { "js": [ "js/companionBubble.js" ], "matches": [ "https://www.figma.com/*", "https://docs.google.com/spreadsheets/*", "https://snowflake.com/*", "https://*.github.com/*", "https://*.airtable.com/*", "https://*.atlassian.net/*", "https://trello.com/", "https://app.hubspot.com/*", "https://www.notion.so/*", "https://*.snowflakecomputing.com/console#/*", "https://app.slack.com/client/*", "https://mail.google.com/*", "https://*.monday.com/*", "https://www.linkedin.com/*", "https://business.facebook.com/*", "https://docs.google.com/presentation/*", "https://app.asana.com/*", "https://docs.google.com/document/*", "https://drive.google.com/drive/*", "https://app.clickup.com/*", "https://*.canva.com/*", "https://*.outreach.io/*", "https://*.salesloft.com/*", "https://meet.google.com/*", "https://*.snowflakecomputing.com/console#/*" ] }, { "js": [ "js/gmail.js" ], "matches": [ "https://mail.google.com/*" ] }, { "js": [ "js/recordConsoleEventsInjector.js" ], "matches": [ "<all_urls>" ] }, { "js": [ "js/recordNetworkEventsInjector.js" ], "matches": [ "<all_urls>" ] }, { "js": [ "js/linkExpand.js" ], "matches": [ "https://github.com/*", "https://gitlab.com/*", "https://app.intercom.io/*", "https://*.intercom.help/*", "https://support.loom.com/*", "https://support.loom.com/*", "https://www.producthunt.com/*", "https://www.dropbox.com/*", "https://news.ycombinator.com/*", "https://docs.google.com/document/*", "https://*.force.com/*", "https://app.salesforceiq.com/*", "https://app.outreach.io/*", "https://app.hubspot.com/*", "https://app.salesloft.com/*" ] } ], "host_permissions": [ "<all_urls>", "*://.loom.com/" ], "manifest_version": 3, "externally_connectable": { "matches": [ "https://www.loom.com/*" ] }, "content_security_policy": { "extension_pages": "script-src 'self' 'wasm-unsafe-eval'; object-src 'self'" }, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "html/bubble.html", "html/pinnedTab.html", "html/permissionsCheck.html", "html/embedView.html", "html/audioVisualizer.html", "html/videoPreview.html", "html/videoPreviewThumbnail.html", "images/allow_site_access.png", "images/ai-avatars-preview.png", "images/avatar-placeholder.svg", "images/blur-ftux.gif", "images/dark-loading-ring.svg", "images/loom-logo-cursor.svg", "images/pinned-tab.png", "images/pinned-tab-preview.png", "images/updated-extension.png", "images/video-limit.png", "images/dragbar_arrow.png", "images/live-rewind-popup.png", "images/os-permission-tutorial.png", "images/camfort/templates/meeting.png", "images/camfort/templates/standup.png", "images/camfort/templates/celebration.png", "images/camfort/templates/news.png", "images/camfort/templates/intro.png", "images/camfort/templates/gradient.png", "images/camfort/templates/rainbow.png", "images/camfort/templates/paint.png", "images/camfort/templates/splash.png", "images/camfort/templates/geometric.png", "images/camfort/templates/flowers.png", "images/camfort/templates/empty.png", "images/camfort/templates/centered.png", "images/camfort/templates/slide_one.png", "images/camfort/templates/slide_two.png", "images/camfort/templates/short_list.png", "images/camfort/templates/long_list.png", "images/camfort/templates/bubbleGoesHereThumbnail.png", "images/gmail/bullets.svg", "images/gmail/bullets-salmon.svg", "images/gmail/compose-button.svg", "images/gmail/gmail-integration-button.svg", "images/blur_hover_preview.png", "images/canvas_hover_preview.png", "images/filter_reference.png", "img/installed.jpg", "fonts/AtlassianSans-cyrillic-ext.woff2", "fonts/AtlassianSans-cyrillic.woff2", "fonts/AtlassianSans-greek-ext.woff2", "fonts/AtlassianSans-greek.woff2", "fonts/AtlassianSans-latin-ext.woff2", "fonts/AtlassianSans-latin.woff2", "fonts/AtlassianSans-vietnamese.woff2", "audio/loom_complete.mp3", "audio/loom_countdown.mp3", "audio/loom_pause.mp3", "audio/loom_start.mp3", "audio/screenshot-shutter.mp3", "images/blurred-ellipse.png", "images/facepile-theme-dark.png", "images/facepile-theme-light.png", "js/muxer.wasm", "js/recordConsoleEvents.js", "js/recordNetworkEvents.js" ] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.