Is Cisco Umbrella Chromebook client (Ext) safe?

Clean risk

Cisco Umbrella Chromebook client sends the domain of every site you visit to its local companion app to enforce DNS content filtering.

On ChromeOS only, the extension intercepts every outgoing web request and sends the visited domain to a companion app running on the device at localhost:8029. If the app's response resolves to one of Cisco's known block/phishing/malware IPs, the extension redirects the tab to a bundled block page instead of loading the site. Results are cached in memory for five minutes per domain and the cache is cleared hourly.

Cisco Systems, Inc.v1.3.4Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.3.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Watch every request your browser makes

    webRequest

  • Schedule its own background tasks

    alarms

  • Store data in your browser

    storage

  • Watch, block and rewrite every request your browser makes

    webRequestBlocking

enterprise.deviceAttributes

Where it sends data

Destinations our analysis observed Cisco Umbrella contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • Cisco Umbrella client app (local companion process, localhost:8029)

    Cisco Umbrella sends data to Cisco Umbrella client app (local companion process, localhost:8029). Named as a recipient in this extension's own analysis.

Updated 21 September 2026jcdhmojfecjfmbdpchihbeilohgnbdci