CRX aminer
Extension icon

Awesome Screen Recorder & Screenshot

Version 4.4.41 View in Chrome Web Store

Last scanned: about 12 hours ago

Extension Details

Developer: http://www.awesomescreenshot.com/
Rating: 4.7 ★ (29.2K ratings)
Users: 4,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has strong user adoption with 4 million users and a high rating of 4.7 stars from nearly 30,000 reviews, suggesting legitimate functionality. The developer website (awesomescreenshot.com) appears to be an established company focused on screenshot and recording tools, which aligns with the extension's stated purpose.

Concerns:

The extension requests extremely broad permissions that extend far beyond basic screenshot functionality. The combination of tabs, cookies, and all_urls host permissions creates a powerful surveillance capability that could access sensitive data across all websites. The unsafe WebAssembly execution policy is particularly concerning as it allows potentially obfuscated malicious code. Content script injection on all HTTP/HTTPS sites, including specific targeting of Gmail, raises privacy concerns about email access. The unlimited storage permission combined with broad data access could enable extensive data collection and retention.

Recommendations:

Given the critical risk level, install this extension only in a separate Chrome profile isolated from sensitive browsing activities. Regularly review what data the extension might be collecting through your browser's privacy settings. Consider alternative screenshot tools with more limited permissions if you don't need advanced recording features. Monitor your browser performance for any unusual activity. If you must use this extension, avoid using it while accessing sensitive websites like banking or personal email accounts.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.