CRX aminer
Extension icon

Blue Prism 7.4 Browser Extension

Version 7.4.0.14058 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Rating: 4.5 ★
Users: 3,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

Blue Prism is a legitimate robotic process automation (RPA) company, and this appears to be their official browser extension for version 7.4 of their platform. The 4.5-star rating and 3,000 users suggest reasonable adoption within their user base. However, the enterprise nature of this tool means it requires extensive permissions to function properly for automation purposes.

Concerns:

The extension's permission set is extremely broad and powerful, which is typical for RPA tools but creates significant security exposure. The combination of tabs, webNavigation, and scripting permissions with unrestricted host access means this extension can monitor all browsing activity, inject code into any website, and potentially access sensitive data across all sites. The nativeMessaging permission allows communication with local applications, expanding the attack surface. While these permissions are likely necessary for Blue Prism's automation functionality, they create substantial risk if the extension is compromised or misused.

Recommendations:

Given the critical risk level, install this extension only in a dedicated Chrome profile used exclusively for Blue Prism automation tasks. Never use this profile for general browsing, banking, or accessing sensitive websites. Ensure you're downloading from the official Chrome Web Store and verify it's the legitimate Blue Prism extension. Only install if you're actively using Blue Prism RPA software and require browser automation capabilities. Regularly audit which websites this extension accesses and remove it immediately when no longer needed for RPA activities.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.