Is Bambuser One-to-One safe?
Bambuser One-to-One removes X-Frame-Options/CSP headers and rewrites consent cookies on merchant sites named in Bambuser's remote config.
The extension powers Bambuser's live-shopping agent dashboard and only accepts commands from lcx.bambuser.com / lcx-eu.bambuser.com. When an agent starts a session it fetches a list of merchant origins from Bambuser's backend and, for those origins, removes X-Frame-Options and Content-Security-Policy response headers (via declarativeNetRequest) so they can be embedded in a co-browse frame. It also injects a MAIN-world script that rewrites configured 'consent' cookies to SameSite=None;Secure and can fetch a merchant page's HTML back to the dashboard. The exact origins, CSP values, and cookie names are not hardcoded - they come entirely from Bambuser's org-settings endpoint.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.