CRX aminer
Extension icon

UiPath Browser Automation 26.10

Version 26.10.1 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Rating: 2.0 ★ (9 ratings)
Users: 400,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

UiPath is a legitimate and well-known robotic process automation (RPA) company with a strong enterprise reputation. The extension has 400,000 users, indicating widespread adoption in business environments. However, the extremely low rating of 2.0 stars from only 9 reviews is concerning and suggests significant user dissatisfaction or functionality issues.

Concerns:

The extensive permission set is appropriate for browser automation but creates substantial security exposure. The management permission allows control over other extensions, while debugger access enables deep system manipulation. The combination of webRequest interception, cookie access, and broad host permissions creates a powerful surveillance capability. The scripting permission with all-URL access means this extension can execute code on any website you visit. The low user rating despite high download numbers suggests potential reliability or privacy issues that users have encountered.

Recommendations:

Given the critical risk level, install this extension only in a dedicated Chrome profile used exclusively for UiPath automation tasks. Never use this profile for personal browsing, banking, or accessing sensitive websites. Regularly audit what automation scripts are running and ensure they come from trusted sources within your organization. Consider using enterprise Chrome policies to restrict this extension's usage to specific domains if possible. Monitor network traffic when the extension is active to detect any unexpected data transmission. Only install if you have a legitimate business need for UiPath browser automation.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: debugger
This extension has the debugger permission. Can debug and manipulate other extensions/apps. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.