Is Поиск Яндексa safe?
Поиск Яндексa is medium risk. On install and every 15 minutes, the extension sends a persistent random UUID plus browser brand, OS, version, install age, banner ID, and extension ID to Yandex analytics. The same IDs ride an uninstall ping too.
Who publishes itJoint-stock company (Aktiengesellschaft) - 4 other listings from the same operator, 1 of them carrying a finding
Joint-stock company (Aktiengesellschaft) - 4 other listings from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
4 other listings published from this account, 12.0M+ users between them. 1 of them carries a finding.
Shared hosts - 4 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Persistent device UUID and metadata sent to Yandex analytics every 15 min
On install and every 15 minutes, the extension sends a persistent random UUID plus browser brand, OS, version, install age, banner ID, and extension ID to Yandex analytics.
The same IDs ride an uninstall ping too.
You install the extension, then simply leave it running.
It assigns your install a permanent random ID and sends it, along with details about your browser and device, to Yandex analytics on install and then every 15 minutes.
No browsing activity or interaction is needed, a background alarm drives the recurring pings on its own.
| Field | Value | Why it matters | |
|---|---|---|---|
Persistent install ID (UUID) | {FB2976F7-3866-DCD8-50CB-AB94976703A8} | A random ID generated once and stored, then reused on every later ping, so all of this install's pings can be tied together over time. | |
Chrome extension ID | fhkbfkkohcdgpckffakhbllifkakihmh | The unique ID of this extension in your browser, sent as the gchid parameter. | |
Browser brand | chromium | Which browser you use (e.g. Chrome, Chromium, Edge, Opera, Yandex), derived from your user-agent. | |
Extension version | 3-0-1-24 | The installed version of the extension. | |
Days since install (dayuse) | 0 | How many days you have had the extension installed, a usage / retention signal. | |
Brand / partner codes | brandID=yandex, clid1=2865315 | Hardcoded campaign identifiers (brandID, clid1, banner ID) that label which distribution channel you came from. |
| User-Agent | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 |
The shipped service-worker code that builds and sends the pings.
// Builds the parameter string for the dayuse analytics ping.
async function buildDayuseVars() {
const installDate = await storage.getDate('application.installDate');
const params = {
dayuse: String(daysSinceInstall(installDate)),
bro: browser.getUserAgent(), // chrome | chromium | edge | opera | yabrowser
productname: 'searchextchrome',
ver: manifestVersion().replaceAll('.', '-'),
ui: await persistentUuid(), // {xxxxxxxx-...} stored + reused
brandID: 'yandex',
clid1: '2865315',
bnrd: await bannerId(),
gchid: chrome.runtime.id // this extension's ID
};
return Object.entries(params).filter(([,v]) => v)
.map(([k,v]) => `-${k}=${encodeURIComponent(v)}`).join(',');
}// On install, fire once after 1 min; then re-arm every 15 min forever.
chrome.runtime.onInstalled.addListener(e => {
if (e.reason === 'install') scheduleSend(1);
});
chrome.alarms.onAlarm.addListener(async a => {
if (a.name === 'statistics_alarm') await sendDailyUsageStats();
});
async function sendDailyUsageStats() {
const last = await storage.getDate('yandex.statistics.time');
if (canSend(last)) {
await storage.setDate('yandex.statistics.time', new Date());
await softExport.send(last ? 'dayuse' : 'install'); // -> soft.export.yandex.ru/status.xml
await dayuse.send(); // -> yandex.ru/clck/click
}
scheduleSend(15); // recurring
}- yandex.ru
Receives the dayuse ping (/clck/click/dtype=elduse) with the UUID and metadata, and the uninstall ping. First-party to Yandex, the extension's publisher.
- soft.export.yandex.ru
Receives the status.xml ping carrying the same UUID, version, OS, brand and extension ID on install and on each recurring fire. First-party Yandex host.
What it can do
Permissions this extension asks for, as declared in version 3.0.1.24. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on chrome-elements.yandex.addons
*://chrome-elements.yandex.addons/
Read and change your data on yandex.by
*://*.yandex.by/
Read and change your data on yandex.com
*://*.yandex.com/
Read and change your data on yandex.com.tr
*://*.yandex.com.tr/
Read and change your data on yandex.kz
*://*.yandex.kz/
Read and change your data on yandex.net
*://*.yandex.net/
Read and change your data on yandex.ru
*://*.yandex.ru/
Read and change your data on yandex.ua
*://*.yandex.ua/
Read and change your data on yandex.uz
*://*.yandex.uz/
Read and change your data on ya.ru
*://*.ya.ru/
Add items to the right-click menu
contextMenus
Schedule its own background tasks
alarms
Read and change cookies, including the ones that keep you signed in
cookies
Store data in your browser
storage
See the address and title of every tab you have open
tabs