Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeBuffer for Safari
Findings · 2
LOW FINDINGS · 2
  1. 01MV3 host_permissions <all_urls> with chrome.scripting.executeScript injecting jQuery + buffer-hover-button.js + keymaster.js into every frame on every navigation completion across the entire web
  2. 02On user-invoked share (context menu, hotkey, popup, hover button), extension reads document.title / og:title / window.getSelection() and forwards page URL + title + selected text + image srcUrl as query parameters to login.buffer.com redirect into publish.buffer.com
OTHER EXTENSIONS

Is Buffer for Safari safe?

Clean risk

No summary available.

Buffer, Inc.v6.0.8Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.buffer.Buffer-Safari.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact