Is Affixa - Gmail (TM) Draft Display safe?

Medium risk

Affixa is medium risk. On load and every 15 minutes after, the extension fetches Google's ListAccounts endpoint to enumerate signed-in accounts. Emails are CRC32-hashed into chrome.storage.local as keys. DA confirmed automatic fetches; undisclosed in the listing.

Notably Good Ltdv5.0.3Chrome Web Store
45Risk
Who publishes it

Notably Good Ltd - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Notably Good Ltd
Declared legal entity
Notably Good Ltd
Registered address
9 Chaucer Place, Wigan WN1 2PL, GB
Registered contact
Notably Good Ltd

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Automatic Google Account Enumeration via ListAccounts API

On load and every 15 minutes after, the extension fetches Google's ListAccounts endpoint to enumerate signed-in accounts.

Emails are CRC32-hashed into chrome.storage.local as keys.

DA confirmed automatic fetches; undisclosed in the listing.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension (or the browser restarts with it enabled).

No login, no button click, and no visit to Gmail is required to trigger account enumeration.

The extension did this

The extension immediately fetches the Google ListAccounts endpoint, harvesting email addresses for every Google account signed into the browser.

The request fires from the background service worker, invisible to the user. Dynamic analysis observed a status-200 GET to accounts.google.com/ListAccounts on first load.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://accounts.google.com/ListAccounts?listPages=0&origin=https%3A%2F%2Fwww.google.com
JSON-like response listing all Google accounts signed into the browser session. Observed during dynamic analysis: HTTP 200, fired from extension background with no user interaction.
Headers
Accept*/*
03EvidenceCODE COMPARE
The code that does this

Account enumeration and hashing in GmailAccountsManager.js

What it actually does
Storage write — CRC32 hash used as a chrome.storage.local keyGmailAccountsManager.js
setAccountComposeLength = async (accountIndex, long) => {
    const val = {};
    const key = `_${this._accounts[accountIndex]}_long`;
    val[key] = long;
    await chrome.storage.local.set(val);
}
04EvidenceSTORAGE DUMP
What's stored on your device

Each key is a CRC32 hash of a signed-in account's email; the boolean flags a 'long' compose window last used. Keys persist across sessions.

Locationchrome.storage.local
Contents (JSON)
{
  "_1234567890_long": false,
  "_2345678901_long": true
}
05EvidenceTEMPORAL PATTERN
When this fires
Every 15 minutes

The ListAccounts fetch repeats every 15 minutes via a chrome.alarms alarm named 'accounts', and also fires each time the user authenticates (InteractiveLogin) or a logstreamz XHR completes in any Gmail tab.

What it can do

Permissions this extension asks for, as declared in version 5.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on mail.google.com

    *://mail.google.com/*

  • Read and change your data on accounts.google.com

    *://accounts.google.com/*

  • Schedule its own background tasks

    alarms

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • Watch every request your browser makes

    webRequest

Updated 30 September 2026ceimgagkkofjoalgojpkdcmhmbljbbaa