Google Meet Enhanced ExperienceSecurity Analysis

Chromev4.0.0MV3February 18, 2026 at 12:11 PM
Use with caution

This extension requests significant permissions. It has 1M+ users, a 3.3 star rating, but review the findings below.

Known Security Incidents(1)

Critical2024-12Resolved

Compromised in Cyberhaven supply chain attack

Extension was among 35+ extensions compromised in the December 2024 supply chain attack campaign that injected data-stealing code.

4.5MEDIUM
4.5 MEDIUMRaw: 5.0

This extension shows some risk signals that are common in legitimate extensions but worth reviewing. Check the details below.

Based on 2 permissions including high-risk ones, 37 code findings.

Trust Signals(3.8/10)

Users
1.0M
Rating
3.3(2K reviews)
Permissions
6.0/10
Code
7.0/10
Combinations
0.0/10
Manifest/CSP
5.0/10

Permissions(2 analyzed)

Code Findings(16 patterns, 37 total)

Content Security Policy

No CSP Defined(1 issue)
MEDIUM
N/ANo CSP defined

This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.

Manifest Analysis(2 findings)

HIGH
web_accessible_resourcesJS files exposed to web pages

JavaScript files are accessible to ALL websites. Any page can load and interact with these scripts, enabling web→extension attacks.

MEDIUM
web_accessible_resources.matchesOverly broad match patterns

Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.

External Domains(3)

arxiv.orggithub.comwww.shadertoy.com

Indicators of Compromise

17 indicators of compromise found

File Statistics

70
Total Files
19
JS Files
7.5 MB
Total Size

Other Scanned Extensions