Chat AI for Chrome
jhhjbaicgmecddbaobeobkikgmfffaeg
Risk Score
4.56
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Default search provider override routes all searches to developer-controlled chataiforchrome.com — classic monetization shell.
- Free-webmail Gmail developer, no developer name listed, no verified publisher badge — unverifiable identity.
- Uninstall URL hijack confirmed; install URL hijack opens developer site on install — aggressive user-funnel manipulation.
- Cookies permission paired with search override creates capability to correlate search queries with session identity.
- Low install count (3,000) with HIGH-tier permissions and monetization shape suggests tail-attack or early-stage monetization shell.
Evidence
- search_provider_override_default manifest chrome_settings_overrides.search_provider.is_default=true; routes searches to chataiforchrome.com/auto-suggest/search.php
- uninstall_url_hijack crx uninstall_url_hijack=true; aggressive retention/tracking on uninstall.
- install_url_hijack crx install_url_hijack=true; target=https://chataiforchrome.com/extension-success/
- free_webmail_no_dev_name store developer_email=nicholascopeland241@gmail.com; developer_name empty; no verified publisher.
- cookies_permission manifest cookies declared alongside search-override; can correlate search queries with session cookies.
- privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true — fully disclosed.
- low_installs_high_perm store 3,000 installs with search-provider override + cookies; monetization shell fingerprint.
- no_cve_no_bad_hosts api cve_findings_raw=[], bad_host_hits=[], monetization_hits=[] — no direct threat-intel hits.
Permissions Breakdown
- storage low Standard local data persistence; low risk.
- cookies high Can read/write cookies; scoped to chataiforchrome.com host only but still HIGH-tier.
- chrome_settings_overrides.search_provider (is_default=true) high Silently replaces default search engine with developer-controlled endpoint.
Pillar Scores
Permissions6.00
Reputation8.00
Network0.00
Webstore8.00
Maintenance1.50
Privacy0.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:45
Listing SHA
b15bf12a4739…
Force block
— not fired
Score recovered
no
Elapsed
—