Is Affixa - Gmail (TM) Draft Display safe?
Affixa is medium risk. On load and every 15 minutes after, the extension fetches Google's ListAccounts endpoint to enumerate signed-in accounts. Emails are CRC32-hashed into chrome.storage.local as keys. DA confirmed automatic fetches; undisclosed in the listing.
Who publishes itNotably Good Ltd - no other listings under this identity
Notably Good Ltd - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Automatic Google Account Enumeration via ListAccounts API
On load and every 15 minutes after, the extension fetches Google's ListAccounts endpoint to enumerate signed-in accounts.
Emails are CRC32-hashed into chrome.storage.local as keys.
DA confirmed automatic fetches; undisclosed in the listing.
You install the extension (or the browser restarts with it enabled).
No login, no button click, and no visit to Gmail is required to trigger account enumeration.
The extension immediately fetches the Google ListAccounts endpoint, harvesting email addresses for every Google account signed into the browser.
The request fires from the background service worker, invisible to the user. Dynamic analysis observed a status-200 GET to accounts.google.com/ListAccounts on first load.
| Accept | */* |
Account enumeration and hashing in GmailAccountsManager.js
setAccountComposeLength = async (accountIndex, long) => {
const val = {};
const key = `_${this._accounts[accountIndex]}_long`;
val[key] = long;
await chrome.storage.local.set(val);
}Each key is a CRC32 hash of a signed-in account's email; the boolean flags a 'long' compose window last used. Keys persist across sessions.
chrome.storage.local{
"_1234567890_long": false,
"_2345678901_long": true
}The ListAccounts fetch repeats every 15 minutes via a chrome.alarms alarm named 'accounts', and also fires each time the user authenticates (InteractiveLogin) or a logstreamz XHR completes in any Gmail tab.
What it can do
Permissions this extension asks for, as declared in version 5.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on mail.google.com
*://mail.google.com/*
Read and change your data on accounts.google.com
*://accounts.google.com/*
Schedule its own background tasks
alarms
Block and redirect the requests your browser makes
declarativeNetRequest
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Watch every request your browser makes
webRequest