CRX aminer

Starting analysis...

Extension icon

SessionBox - Multi login to any website

Version 1.8.9 View in Chrome Web Store

Last scanned: over 1 year ago | force re-scan

Extension Details

Developer: sessionbox.io
Rating: 3.3 ★ (1.4K ratings)
Size: 2.62MiB
Last Updated: September 10, 2024
Users: 200,000
Developer Info: Box Labs Kft.Nádasdy utca 15-A 2. emelet 18 Budapest 1097 HU

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:
- The extension has a relatively high number of users (200,000), which could indicate some level of trust and popularity.
- However, the average rating is quite low at 3.3/5 from 1.4K reviews, suggesting potential issues or concerns from users.
- The developer information provided seems legitimate (a company based in Hungary), but further verification may be needed.
Concerns:
- This extension requests an extremely broad set of permissions, including the ability to access all websites, intercept and modify web requests/traffic, manage browser tabs and cookies, and more. Many of these permissions seem unnecessary for the stated functionality of allowing multi-login to websites.
- The combination of certain permissions (e.g., webRequest and webRequestBlocking) could potentially be used for malicious purposes, such as modifying sensitive web traffic or stealing data.
- The extension can inject scripts into any website, raising concerns about potential data theft or content modification.
- The use of an older manifest version (v2) means fewer security restrictions compared to the newer v3.
Recommendations:
- Exercise extreme caution when considering the installation of this extension, as the broad permissions and potential risks appear to outweigh the stated functionality.
- If you decide to use this extension, consider running it in a separate browser profile or a dedicated testing environment to isolate it from your primary browsing activities.
- Regularly monitor the extension's behavior and check for any suspicious activities or performance issues.
- Consider exploring alternative solutions or extensions with more limited and specific permissions that align with their stated functionality.
- Report any concerns or issues to the extension developer or the appropriate authorities if you suspect malicious behavior.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Dangerous Permission Combination: webRequest + webRequestBlocking
This extension can intercept, modify, and block web requests in real-time. This combination could be used to modify sensitive web traffic or steal data.
HIGH
High-Risk Permission: <all_urls>
This extension has the <all_urls> permission. Can access all websites and their content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequestBlocking
This extension has the webRequestBlocking permission. Can block and modify web requests in real-time. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.