CRX aminer
Extension icon

iCloud Passwords

Version 3.3.0 View in Chrome Web Store

Last scanned: about 12 hours ago

Extension Details

Rating: 2.3 ★ (2.5K ratings)
Users: 6,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has 6 million users, indicating widespread adoption, but the concerning 2.3-star rating from 2,500 reviews suggests significant user dissatisfaction. While this appears to be Apple's official iCloud Passwords extension for Chrome, the poor rating raises questions about functionality and user experience rather than malicious intent.

Concerns:

The extension requests extremely broad permissions that are excessive for a password manager. The privacy permission allows modification of browser privacy settings, which is unnecessary for password autofill functionality. The webNavigation permission enables comprehensive browsing tracking across all websites. Most concerning is the combination of broad host permissions (*://*/*) with content script injection capabilities, allowing the extension to access and potentially modify any website's content. The nativeMessaging permission, while legitimate for communicating with the iCloud Passwords desktop application, adds another attack vector if compromised.

Recommendations:

Despite being from Apple, the overly broad permissions present significant privacy and security risks. Consider running this extension in a separate Chrome profile dedicated solely to password management activities. Alternatively, evaluate whether Apple's built-in password management through Safari or dedicated password managers with more restrictive permissions would better serve your needs. If you must use this extension, regularly review your privacy settings and monitor for any unexpected changes to your browsing experience.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: privacy
This extension has the privacy permission. Can modify privacy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.