Is ブラウザ切替機能2 for Google Workspace™ <サテライトオフィス> safe?
サテライトオフィス ブラウザ切替機能 is medium risk. DA confirmed Gmail makes this extension send your email and Workspace domain to the vendor's server (sateraito-apps-browser.appspot.com) as a plain-text query param, unprompted. The vendor returns rules for opening URLs in IE/Firefox/Edge.
Who publishes it株式会社サテライトオフィス - 4 other listings from the same operator, none carrying a finding
株式会社サテライトオフィス - 4 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
4 other listings published from this account, 310k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Gmail email address sent to vendor server on every page load
DA confirmed Gmail makes this extension send your email and Workspace domain to the vendor's server (sateraito-apps-browser.appspot.com) as a plain-text query param, unprompted.
The vendor returns rules for opening URLs in IE/Firefox/Edge.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-359
- Source
- Dynamic sandbox
You open Gmail in Chrome.
The extension's content script runs automatically on mail.google.com.
The extension sends your full email address to the vendor's server as a URL query parameter.
No prompt is shown. The request fires as part of fetching the organization's browser-routing configuration.
JSON object containing URL routing rules (ieRegexUrl, crmLeftUrl, etc.) for the organization's domain. Response is cached locally for 10 minutes.
- Accept
- application/json
- Your email addressalice@example.com
Your full Google account email is sent URL-encoded in the oauth2email parameter on every Gmail page load.
- Your organization's domainexample.com
The part of your email after the @ sign is sent as the URL path segment, identifying your employer or organization to the vendor.
- Request timestamp1780702476932
A millisecond-precision timestamp is included as the rk parameter, allowing the server to correlate requests over time.
Content script extracts email from Gmail DOM (bsw_c.js)
// bsw_c.js — reads email address from Gmail header DOM elementvar emailText = domNode.textContent.trim();var parts = emailText.split('@');if (parts.length === 2) { var domain = parts[1] || ''; window.localStorage.setItem('__StGAddrDOM__', domain); var result = { domain: domain, email: emailText }; return result; // returned to sendMessage call below}// then: chrome.runtime.sendMessage({ method: 'updateOption', domain, email })Background service worker constructs and fires the request (bsw_b.js)
// bsw_b.js — function ib(), called when updateOption message arrives from content scriptfunction requestSettings(msg) { function buildUrl() { var url = 'https://sateraito-apps-browser.appspot.com/j/' + msg.domain + '?v=2&rk=' + Date.now(); if (msg.email) { url += '&oauth2email=' + encodeURIComponent(msg.email); // full email in query string } return url; } // fires immediately unless a 10-minute local cache is valid}- sateraito-apps-browser.appspot.com
Vendor configuration server (Sateraito Office, Japan). Receives the user's email and org domain to return per-org browser URL routing rules. Hosted on Google App Engine.
What it can do
Permissions this extension asks for, as declared in version 1.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on sateraito-apps-browser.appspot.com
https://sateraito-apps-browser.appspot.com/
Read and change your data on google.com
https://*.google.com/
See the address and title of every tab you have open
tabs
Store data in your browser
storage
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
See every page you navigate to, as you navigate to it
webNavigation