Is Bambuser One-to-One safe?

Clean risk

Bambuser One-to-One removes X-Frame-Options/CSP headers and rewrites consent cookies on merchant sites named in Bambuser's remote config.

The extension powers Bambuser's live-shopping agent dashboard and only accepts commands from lcx.bambuser.com / lcx-eu.bambuser.com. When an agent starts a session it fetches a list of merchant origins from Bambuser's backend and, for those origins, removes X-Frame-Options and Content-Security-Policy response headers (via declarativeNetRequest) so they can be embedded in a co-browse frame. It also injects a MAIN-world script that rewrites configured 'consent' cookies to SameSite=None;Secure and can fetch a merchant page's HTML back to the dashboard. The exact origins, CSP values, and cookie names are not hardcoded - they come entirely from Bambuser's org-settings endpoint.

Bambuserv1.0.10Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

svc-prod-us.liveshopping.bambuser.comsvc-prod-eu.liveshopping.bambuser.comlcx.bambuser.comlcx-eu.bambuser.com
Updated 17 September 2026fkhddgplfbdjopphepkohfgdkikfleai