Is Custom profile picture for Netflix™ [QVI] safe?

Medium risk

Custom Profile Picture for Netflix is medium risk. On install, the extension marks data collection enabled unasked. Before consent, it sends a tracking ID plus your viewing history, profile data, device lists, and watch-lists to metricsplus.online. No opt-out at install; only in settings.

Great Browser Extensionsv1.2.9.82Chrome Web Store
45Risk
Who publishes it

HideApp - 67 other listings from the same operator, 15 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Great Browser Extensions
Declared legal entity
HideApp
Registered address
1021 East Lincolnway, Cheyenne, WY 82001, US
Registered contact
HideApp LLC

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Viewing Data Sent Without Consent Prompt

On install, the extension marks data collection enabled unasked.

Before consent, it sends a tracking ID plus your viewing history, profile data, device lists, and watch-lists to metricsplus.online.

No opt-out at install; only in settings.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension from the Chrome Web Store.

No consent prompt for data sharing is displayed during or immediately after installation.

The extension did this

The service worker writes shareInsights=true to chrome.storage.sync, enabling data collection.

Dynamic analysis confirmed this flag is set before any onboarding flow completes and before you visit Netflix for the first time.

02EvidenceSTORAGE DUMP
What's stored on your device

Controls whether viewing data goes to metricsplus.online. Set true on every fresh install unasked, so collection runs until manual opt-out.

Locationchrome.storage.sync key 'shareInsights'
Contents (JSON)
{
  "shareInsights": true
}
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://metricsplus.online/n/js/dlog
Body
{
  "dist": "chrome",
  "revision": "4e389220",
  "platform": "netflix",
  "namespace": "flow",
  "extVer": "1.2.9.71",
  "extensionUserId": "795cda2d-a3f1-4e22-b918-c7d04e2b1f93",
  "dhVer": "3.1.0",
  "message": "init"
}
04EvidenceFIELD TABLE
Data fields transmitted to metricsplus.online
FieldValueWhy it matters
Extension user ID
795cda2d-a3f1-4e22-b918-c7d04e2b1f93A random ID from first install, stored in your browser, letting metricsplus.online link uploads across sessions.
Netflix account ID and profile GUID
accountId: 2001298374, profileId: a1b2c3d4-e5f6-7890-abcd-ef1234567890Your Netflix account ID and profile GUID are pulled from the page and sent in the session-init request.
Netflix viewing history
Squid Game, Bridgerton, Cobra Kai, Money Heist, The WitcherTitles from up to five pages (500 items) of viewing history are uploaded when shareInsights is enabled.
Country and browser language
country: US, browserLanguage: en-USYour device locale and inferred country code are included in every session-init request sent to metricsplus.online.
Extension version and build revision
extVer: 1.2.9.71, revision: 4e389220Version and build revision are sent with every request, letting the server segment data by release.
05EvidenceCODE COMPARE
The code that does this

sw.js: consent flag set to true on install (no prompt)

What it actually does
// Runs once when the extension is first installed.
// At this point the user has NOT been asked about data sharing.
chrome.runtime.onInstalled.addListener(async (event) => {
  const { reason } = event;

  if (reason === chrome.runtime.OnInstalledReason.INSTALL) {
    initConfig();       // creates a local profile-picture config in chrome.storage.local
    openSuccessPage();  // opens greatbrowserextensions.com/thank-you-survey/ in a new tab
  } else if (reason === chrome.runtime.OnInstalledReason.UPDATE) {
    applyLegacyMigration();
  }

  reloadNetflix(); // reloads any open Netflix tabs so content scripts activate

  // Set data collection to ON by default — no consent prompt is shown.
  // If shareInsights is not already set (i.e., fresh install), write true.
  chrome.storage.sync.get(['shareInsights'], (result) => {
    if (result.shareInsights === undefined) {
      chrome.storage.sync.set({ shareInsights: true }); // DATA COLLECTION ACTIVE
    }
  });
});
06EvidenceTHIRD PARTY LIST
Domains receiving extension data
  • metricsplus.online

    Primary endpoint. Receives telemetry (/n/js/dlog), session-init data at /n/netflix/start, and viewing/profile data at /n/netflix/upload. Hardcoded across all eleven bundles.

  • metricsmint.quest

    Secondary upload endpoint, config key 'd1', across eight bundles. Role undocumented in the listing or privacy policy.

Updated 30 September 2026olimcenppncifgiahopimblidefpdffi