CRX aminer

Starting analysis...

Extension icon

Surf Security 5

Version 1.4.118 View in Chrome Web Store

Last scanned: 2 months ago | force re-scan

Extension Details

Rating: 3.0 ★
Users: 2,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: This extension has several concerning trust indicators. With only 2,000 users and a low 3.0 rating, it lacks widespread adoption and user confidence. The generic name "Surf Security 5" with no clear developer information raises authenticity concerns. The absence of detailed description makes it difficult to verify legitimate security purposes.
Concerns: The permission set is extremely invasive for any extension, especially one with questionable credentials. The combination of proxy control, identity access, cookie manipulation, and management permissions creates a perfect storm for malicious activity. The extension can intercept all web traffic through proxy settings, steal authentication cookies, access personal identity information, and even manage other extensions. The broad host permissions across all websites amplify these risks significantly. The system.cpu permission adds another layer of concern, potentially enabling resource-intensive operations. The nativeMessaging permission suggests communication with external applications, which could facilitate data exfiltration.
Recommendations: Do not install this extension under any circumstances given the critical risk level and lack of trustworthy developer information. If security functionality is needed, choose well-established alternatives from reputable companies with transparent privacy policies and strong user bases. The permission combination suggests potential malware rather than legitimate security software. Consider reporting this extension to Chrome Web Store for review.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.