CRX aminer
Extension icon

Loom – Screen Recorder & Screen Capture

Version 5.5.186 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: loom.com
Rating: 4.6 ★ (10.2K ratings)
Users: 8,000,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

Loom is a well-established company with a legitimate screen recording service. The extension has 8 million users and a strong 4.6-star rating from over 10,000 reviews, indicating widespread adoption and user satisfaction. The developer is the official loom.com domain, adding credibility to the extension's authenticity.

Concerns:

While Loom's functionality justifies many permissions, several raise privacy concerns. The cookies permission combined with webRequest and webNavigation allows comprehensive tracking of browsing behavior. The broad host permissions (<all_urls>) and content script injection capabilities mean Loom can access sensitive data on any website you visit. The system.memory and system.cpu permissions, while useful for performance optimization, provide deep system access. The unsafe WebAssembly execution policy creates potential security vulnerabilities.

The extensive list of specific content scripts targeting popular business platforms (Gmail, Slack, Notion, etc.) suggests deep integration but also means Loom can access sensitive business communications and documents.

Recommendations:

Given Loom's legitimate business purpose and strong reputation, the risk is manageable for most users. However, privacy-conscious users should consider running it in a separate Chrome profile to isolate its broad access. Review your Loom privacy settings and consider disabling the extension when not actively recording. For highly sensitive work environments, evaluate whether the convenience justifies the extensive data access permissions.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.