Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeBrex Browser Extension
Findings · 3
+1 more finding locked
LOW FINDINGS · 3
  1. 01The OAuth authorization URL — which embeds the PKCE code_challenge, state token, redirect_uri, client_id and requested scopes — is transmitted to the third-party Segment telemetry endpoint as the `login.url` event property.
  2. 02Background script sends product telemetry (login lifecycle, token refresh, receipt upload events) to api.segment.io using a hardcoded Segment write key, identifying users by their Brex userId.
  3. 03Popup uses chrome.tabs.captureVisibleTab to take a screenshot of the user's active tab and upload it to platform.brexapis.com as a receipt attachment.
+1 more finding locked
OTHER EXTENSIONS

Is Brex Browser Extension safe?

Low risk

No summary available.

Brexv1.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.brex.browser.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact