Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeCitrix Workspace Web Extension
Findings · 3
+1 more finding locked
HIGH FINDINGS · 3
  1. 01Content script on <all_urls> bridges arbitrary page CustomEvents to chrome.runtime.sendMessage, bypassing the externally_connectable allowlist (*://*.cloud.com/*) and exposing the full background message-router (icaLaunch, leaseLaunch, initiateStore, appConfigFetchWithToken, sendTabToOfflineUrlInternal, etc.) to any origin
  2. 02Background handler `sendTabToOfflineUrlInternal` lets any origin redirect the active tab to an arbitrary URL via chrome.tabs.update; the only sanitization is appending `#/ctxOffline` to the supplied URL
  3. 03`isStoreUrl` / `isCitrixStoreUrl` regex `https{0,1}://[\w|\.|\-]+/Citrix/.*` accepts plaintext HTTP and any hostname, allowing a malicious site to register itself as the active Citrix store tab and receive forwarded AAD OAuth auth-codes
+1 more finding locked
OTHER EXTENSIONS

Is Citrix Workspace Web Extension safe?

High risk

No summary available.

Citrix Systems, Inc.v25.7.3Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.citrix.workspace-safari-web-extension.mac.bridge

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact