Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeCNET Shopping
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01Product data (title, price, brand, SKU, UPC, model) scraped from all retail pages and sent to shopping.cnet.com with persistent user ID
  2. 02Remote scraping configuration (XPath/CSS selectors, coupon apply logic) fetched from shopping.cnet.com determines what data is extracted from all retailer pages
  3. 03webScript.js injected into page context listens to postMessage with no origin validation, allowing any page script to trigger window.alert/confirm suppression or read window variables
+2 more findings locked
OTHER EXTENSIONS

Is CNET Shopping safe?

Medium risk

No summary available.

CNET Shopping Extensionv14.25Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026lghjfnfolmcikomdjmoiemllfnlmmoko

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact