Is Поиск Яндексa safe?

Medium risk

Поиск Яндексa is medium risk. On install and every 15 minutes, the extension sends a persistent random UUID plus browser brand, OS, version, install age, banner ID, and extension ID to Yandex analytics. The same IDs ride an uninstall ping too.

Yandexv3.0.1.24Chrome Web Store
45Risk
Who publishes it

Joint-stock company (Aktiengesellschaft) - 4 other listings from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Yandex
Declared legal entity
Joint-stock company (Aktiengesellschaft)
Registered address
Werftestrasse 4, Luzern 6005, CH
Registered contact
Intertech Services AG

Same store account

4 other listings published from this account, 12.0M+ users between them. 1 of them carries a finding.

Shared hosts - 4 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

suggest.yandex.net
Also called by 5 other listings, including Поиск Яндексa, Поиск Яндексa
browser.yandex.ru
Also called by 7 other listings, including Поиск Яндексa, Поиск Яндексa, Визуальные закладки
chrome-elements.yandex.addons
Also called by 7 other listings, including Поиск Яндексa, Поиск Яндексa
yandex.net
Also called by 8 other listings, including Поиск Яндексa, Поиск Яндексa

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Persistent device UUID and metadata sent to Yandex analytics every 15 min

On install and every 15 minutes, the extension sends a persistent random UUID plus browser brand, OS, version, install age, banner ID, and extension ID to Yandex analytics.

The same IDs ride an uninstall ping too.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension, then simply leave it running.

The extension did this

It assigns your install a permanent random ID and sends it, along with details about your browser and device, to Yandex analytics on install and then every 15 minutes.

No browsing activity or interaction is needed, a background alarm drives the recurring pings on its own.

02EvidenceFIELD TABLE
What is attached to each analytics ping:
FieldValueWhy it matters
Persistent install ID (UUID)
{FB2976F7-3866-DCD8-50CB-AB94976703A8}A random ID generated once and stored, then reused on every later ping, so all of this install's pings can be tied together over time.
Chrome extension ID
fhkbfkkohcdgpckffakhbllifkakihmhThe unique ID of this extension in your browser, sent as the gchid parameter.
Browser brand
chromiumWhich browser you use (e.g. Chrome, Chromium, Edge, Opera, Yandex), derived from your user-agent.
Extension version
3-0-1-24The installed version of the extension.
Days since install (dayuse)
0How many days you have had the extension installed, a usage / retention signal.
Brand / partner codes
brandID=yandex, clid1=2865315Hardcoded campaign identifiers (brandID, clid1, banner ID) that label which distribution channel you came from.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://yandex.ru/clck/click/dtype=elduse/path=tech.yaelements.dayuse/vars=-dayuse=0,-bro=chromium,-productname=searchextchrome,-ver=3-0-1-24,-ui=%7BFB2976F7-3866-DCD8-50CB-AB94976703A8%7D,-brandID=yandex,-clid1=2865315,-gchid=fhkbfkkohcdgpckffakhbllifkakihmh/slots=0,0,0/*
Headers
User-AgentMozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
04EvidenceCODE COMPARE
The code that does this

The shipped service-worker code that builds and sends the pings.

What it actually does
Day-use ping assembler
// Builds the parameter string for the dayuse analytics ping.
async function buildDayuseVars() {
  const installDate = await storage.getDate('application.installDate');
  const params = {
    dayuse: String(daysSinceInstall(installDate)),
    bro: browser.getUserAgent(),            // chrome | chromium | edge | opera | yabrowser
    productname: 'searchextchrome',
    ver: manifestVersion().replaceAll('.', '-'),
    ui: await persistentUuid(),             // {xxxxxxxx-...} stored + reused
    brandID: 'yandex',
    clid1: '2865315',
    bnrd: await bannerId(),
    gchid: chrome.runtime.id                 // this extension's ID
  };
  return Object.entries(params).filter(([,v]) => v)
    .map(([k,v]) => `-${k}=${encodeURIComponent(v)}`).join(',');
}
Recurring 15-minute alarm scheduler
// On install, fire once after 1 min; then re-arm every 15 min forever.
chrome.runtime.onInstalled.addListener(e => {
  if (e.reason === 'install') scheduleSend(1);
});
chrome.alarms.onAlarm.addListener(async a => {
  if (a.name === 'statistics_alarm') await sendDailyUsageStats();
});
async function sendDailyUsageStats() {
  const last = await storage.getDate('yandex.statistics.time');
  if (canSend(last)) {
    await storage.setDate('yandex.statistics.time', new Date());
    await softExport.send(last ? 'dayuse' : 'install'); // -> soft.export.yandex.ru/status.xml
    await dayuse.send();                                  // -> yandex.ru/clck/click
  }
  scheduleSend(15); // recurring
}
05EvidenceTHIRD PARTY LIST
Where the identifiers and metadata are sent:
  • yandex.ru

    Receives the dayuse ping (/clck/click/dtype=elduse) with the UUID and metadata, and the uninstall ping. First-party to Yandex, the extension's publisher.

  • soft.export.yandex.ru

    Receives the status.xml ping carrying the same UUID, version, OS, brand and extension ID on install and on each recurring fire. First-party Yandex host.

What it can do

Permissions this extension asks for, as declared in version 3.0.1.24. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on chrome-elements.yandex.addons

    *://chrome-elements.yandex.addons/

  • Read and change your data on yandex.by

    *://*.yandex.by/

  • Read and change your data on yandex.com

    *://*.yandex.com/

  • Read and change your data on yandex.com.tr

    *://*.yandex.com.tr/

  • Read and change your data on yandex.kz

    *://*.yandex.kz/

  • Read and change your data on yandex.net

    *://*.yandex.net/

  • Read and change your data on yandex.ru

    *://*.yandex.ru/

  • Read and change your data on yandex.ua

    *://*.yandex.ua/

  • Read and change your data on yandex.uz

    *://*.yandex.uz/

  • Read and change your data on ya.ru

    *://*.ya.ru/

  • Add items to the right-click menu

    contextMenus

  • Schedule its own background tasks

    alarms

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026fhkbfkkohcdgpckffakhbllifkakihmh