Is AHA Music - Song Finder for Browser safe?
AHA Music sends your Google email, a persistent device ID, and active tab URL to extension.doreso.com on every popup open.
Each time the popup opens, the extension retrieves your Google account email and a persistent random device ID from sync storage, then sends both along with your browser version and locale to extension.doreso.com before you click anything. When you trigger a music search, it also collects the active tab's URL and page title and includes them in the audio identification request. The device ID persists across browser sessions and Chrome profile syncs, allowing the extension's servers to track your activity over time.
Who publishes itACRCloud - no other listings under this identity, 2 shared hostnames
ACRCloud - no other listings under this identity, 2 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Popup Sends Google Email and Persistent Device ID to Doreso.com
Every time you open the AHA Music popup, it contacts extension.doreso.com with your signed-in Google email, a persistent device ID, User-Agent, and locale.
The device ID, stored in your synced profile, tracks your browser across restarts.
You click the AHA Music toolbar icon to open the popup.
The extension immediately contacts extension.doreso.com, transmitting your Google account email, a persistent device identifier, your browser's User-Agent string, and your locale.
This request fires before you interact with any music-recognition feature.
| Field | Value | Why it matters | |
|---|---|---|---|
Google account email | user@example.com | Your signed-in Google account email address. Empty if you are not signed into Chrome with a Google account. | |
Device ID | 78234_1718901234567 | A random ID generated once and stored in your synced profile, letting the server recognize your browser across restarts and devices. | |
Browser version (User-Agent) | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | Your full browser User-Agent string, which reveals your browser type, version, and operating system. | |
Browser locale | en-US | Your browser's language and region setting, as returned by chrome.i18n.getUILanguage(). |
Shipped minified source: device ID generation and config fetch
get_device_id() {
return new Promise((resolve) => {
chrome.storage.sync.get('device_id', (result) => {
let id = result['device_id'];
if (!id) {
// First run: generate a random ID and persist it to Chrome Sync
id = parseInt(100000 * Math.random()) + '_' + new Date().getTime();
chrome.storage.sync.set({ device_id: id });
}
resolve(id);
});
});
}initConfig() {
// configUrl = 'https://extension.doreso.com/v1/aha-music/config'
axios.get(this.configUrl, {
params: {
email: this.userInfo['email'], // Google account email
device_id: this.userInfo['device_id'], // persistent cross-session tracker
browser_version: this.userInfo['browser_version'], // navigator.userAgent
local_lan: this.userInfo['local_lan'] // chrome.i18n.getUILanguage()
}
}).then((response) => {
const data = response.data;
if (data['status'] === 0) {
this.configInfo = data['data'];
this.$storage_helper.setConfig(data['data']); // cache ads config locally
}
});
}// Fires immediately when the popup opens
chrome.identity.getProfileUserInfo((userInfo) => {
let email = '';
let googleId = '';
if (userInfo) {
email = userInfo['email']; // Google account address
googleId = userInfo['id'];
}
const locale = chrome.i18n.getUILanguage() || navigator.language;
const manifestVersion = chrome.runtime.getManifest();
this.userInfo['local_lan'] = locale;
this.userInfo['app_id'] = chrome.runtime.id;
this.userInfo['version'] = manifestVersion.version;
this.userInfo['email'] = email;
this.userInfo['google_id'] = googleId;
this.userInfo['browser_version'] = navigator.userAgent;
// Then read (or generate) the persistent device ID, then fire config fetch
this.$storage_helper.get_device_id().then((deviceId) => {
this.userInfo['device_id'] = deviceId;
this.initConfig(); // transmits email + deviceId + UA + locale to doreso.com
});
});- extension.doreso.com
Doreso Inc., AHA Music backend. Receives email, persistent device ID, User-Agent, and locale on every popup open. Returns ad configuration displayed in the extension popup.
What it can do
Permissions this extension asks for, as declared in version 2.0.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Sign you in with your Google account
identity
See the email address of your Google account
identity.email
Store data in your browser
storage
Store an unlimited amount of data in your browser
unlimitedStorage
Act on the current tab, but only after you click the extension
activeTab
Capture the video and audio of a tab
tabCapture
Where it sends data
Destinations our analysis observed AHA Music contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- extension.doreso.com
AHA Music sends data to extension.doreso.com. One other extension we have analysed sends data here.