Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeCastBuddy
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Content script window.postMessage listener has no origin validation, allowing any page script to inject arbitrary video URLs into the extension's playlist on any website
  2. 02Content script broadcasts a fingerprinting postMessage to all origins on every tab navigation, revealing CastBuddy extension presence to any page script
  3. 03Content script reads document.title and current page URL (iframeURL) from every HTTP/HTTPS page and sends them to the background service worker on each navigation
OTHER EXTENSIONS

Is CastBuddy safe?

Medium risk

No summary available.

b4tv3.0.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026ghagedffjalchgcgdgfindabkpnmalel

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact