Is Поиск Яндексa safe?
Поиск Яндекса transmits a persistent UUID, browser brand, OS, and extension version to Yandex analytics every 15 minutes.
On a recurring 15-minute alarm, the extension sends a generated user identifier stored as `yandex.statistics.ui` together with browser brand, OS, extension version, and CLID codes to `https://yandex.ru/clck/click/dtype=elduse`. It also writes a cookie named `ext-{extensionId}` encoding install date, update date, and timestamp to Yandex new-tab pages across multiple TLDs (ru, ua, by, kz, com.tr), and injects the extension version into the `ys` cookie on all root Yandex domains. At install time, the extension queries all open tabs to locate the Chrome Web Store page and extract the `banerid` URL parameter, which is included in subsequent telemetry calls.
Who publishes itJoint-stock company (Aktiengesellschaft) - 4 other listings from the same operator, 1 of them carrying a finding
Joint-stock company (Aktiengesellschaft) - 4 other listings from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
4 other listings published from this account, 12.0M+ users between them. 1 of them carries a finding.
Shared hosts - 4 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Yandex Search Sends Persistent UUID and Browser Fingerprint Every 15 Minutes
Dynamic analysis captured the extension sending a persistent UUID, browser brand, version, and partner codes to Yandex at startup and every 15 min.
A second endpoint gets the same UUID at install and daily use, undisclosed in the listing.
You install the Yandex Search extension, or your browser starts up with it already installed.
The extension transmits a persistent UUID along with your browser brand, OS, and extension version to Yandex analytics endpoints.
The same UUID is sent again every 15 minutes via a background alarm, regardless of whether you use the extension.
| Field | Value | Why it matters | |
|---|---|---|---|
Your persistent UUID | {66E44EBC-89A9-7288-3063-2D0455286F1A} | A unique identifier generated when the extension first runs, stored permanently. Allows Yandex to recognize your browser across sessions. | |
Browser brand | chromium | Which browser you are using (e.g. Chrome, Chromium, Edge). | |
Extension version | 3-0-0-24 | The exact version of the Yandex Search extension you have installed. | |
Partner / brand ID | brandID=yandex, clid1=2865315 | Hardcoded partner codes (brandID, clid1) identifying this extension build to Yandex's analytics system. | |
Extension runtime ID | ldgpjdiadomhinpimgchmeembbgojnjk | The Chrome-assigned ID for this extension, a second stable identifier sent alongside the UUID. | |
Daily-use counter | 0 | Counts how many days since install the extension has been active. Reveals how long you have had it installed. |
After the first send (1 minute after install or startup), the extension reschedules itself every 15 minutes using chrome.alarms. The alarm fires regardless of user activity.
The source code that assembles and sends the 15-minute analytics ping:
// Reads UUID from cookie (chrome-elements.yandex.addons) or chrome.storage.local.
// If neither exists, generates a new UUID-shaped string and stores it in both.
const UIDManager = {
async getValue() {
const cookieValue = await CookieStore.get('yandex.statistics.ui');
const storedValue = await Storage.get('yandex.statistics.yandexUi')
|| await Storage.get('application.ui');
let uid = typeof cookieValue === 'string' ? cookieValue : storedValue;
if (!uid) uid = this.generateValue();
// Persist to both cookie and storage for next time
if (uid && typeof cookieValue !== 'string') CookieStore.set('yandex.statistics.ui', uid);
if (uid && !storedValue) await Storage.set('application.ui', uid);
return uid;
},
generateValue() {
// Produces a UUID like {66E44EBC-89A9-7288-3063-2D0455286F1A}
return '{xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx}'
.split('')
.map(c => c !== 'x' ? c : '0123456789ABCDEF'[Math.floor(16 * Math.random())])
.join('');
}
};async function buildDayuseParams() {
const installDate = await Storage.getDate('application.installDate');
const params = {
dayuse: String(daysSinceInstall(installDate)), // days active
bro: BrowserDetector.getUserAgent(), // 'chromium', 'chrome', etc.
productname: config.get('yasoft'), // 'searchextchrome'
ver: Manifest.getVersion('-'), // '3-0-0-24'
ui: await UIDManager.getValue(), // persistent UUID
brandID: config.get('brandId'), // 'yandex'
clid1: await CLIDStore.get(1), // '2865315'
bnrd: await BannerID.getValue(), // banerid from CWS install URL
gchid: chrome.runtime.id // extension's own Chrome ID
};
return Object.keys(params)
.filter(k => params[k])
.map(k => `-${k}=${encodeURIComponent(params[k])}`)
.join(',');
}async function sendDailyUsageStats() {
const lastSentTime = await Storage.getDate('yandex.statistics.time');
if (this.canSend(lastSentTime)) {
await Storage.setDate('yandex.statistics.time', new Date());
// Also sends to soft.export.yandex.ru
await SoftExport.send(lastSentTime ? 'dayuse' : 'install');
// Sends the dayuse ping to yandex.ru/clck/click/dtype=elduse
await DayuseStats.send();
}
// Reschedule for 15 minutes from now — runs indefinitely
this.scheduleNextSend(15);
}- yandex.ru
Primary analytics receiver. /clck/click/dtype=elduse gets the 15-min dayuse ping; dtype=stred gets error reports. Both include the persistent UUID.
- soft.export.yandex.ru
Secondary analytics endpoint. Receives UUID, version, OS, install/dayuse flags on install and the daily-use alarm. Confirmed in dynamic analysis.
What it can do
Permissions this extension asks for, as declared in version 3.0.0.24. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on chrome-elements.yandex.addons
*://chrome-elements.yandex.addons/
Read and change your data on yandex.by
*://*.yandex.by/
Read and change your data on yandex.com
*://*.yandex.com/
Read and change your data on yandex.com.tr
*://*.yandex.com.tr/
Read and change your data on yandex.kz
*://*.yandex.kz/
Read and change your data on yandex.net
*://*.yandex.net/
Read and change your data on yandex.ru
*://*.yandex.ru/
Read and change your data on yandex.ua
*://*.yandex.ua/
Read and change your data on yandex.uz
*://*.yandex.uz/
Read and change your data on ya.ru
*://*.ya.ru/
Schedule its own background tasks
alarms
Read and change cookies, including the ones that keep you signed in
cookies
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Where it sends data
Destinations our analysis observed Поиск Яндексa contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- yandex.ru
Поиск Яндексa sends data to yandex.ru. 10 other extensions we have analysed send data here.
- soft.export.yandex.ru
Поиск Яндексa sends data to soft.export.yandex.ru. 3 other extensions we have analysed send data here.