CRX aminer
Extension icon

Video Downloader Global - videos & streams

Version 1.2.8 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Rating: 4.3 ★ (89 ratings)
Users: 20,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension has a moderate user base of 20,000 users and a decent rating of 4.3 stars from 89 reviews, which suggests some level of user satisfaction. However, the lack of clear developer information and company details reduces trustworthiness. Video downloaders are inherently risky as they often require extensive permissions to function across various video platforms.
Concerns: This extension exhibits multiple red flags that justify the critical risk rating. The combination of broad host permissions with content script injection capabilities creates a dangerous attack surface, allowing the extension to access and manipulate data on every website you visit. The webRequest permission enables traffic interception, which could be exploited for credential theft or data exfiltration. The unsafe WebAssembly execution policy is particularly concerning as it allows potentially obfuscated malicious code to run. The downloads permission, while necessary for the extension's function, adds another vector for potential abuse.
Recommendations: Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile specifically for video downloading activities, ensuring no sensitive accounts are logged in. Consider using established, well-reviewed alternatives from reputable developers. Monitor your download folder for unexpected files and regularly review the extension's network activity. Be extremely cautious about using this extension on websites where you handle sensitive information like banking or personal accounts.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.