Is Cyber-Ark Clipboard Extension safe?

Low risk

Cyber-Ark Clipboard Extension adds a clipboard-write bridge to every page that any in-page script can use to overwrite clipboard contents.

The extension runs a content script on all http and https pages. When a page sets the HTML attribute ca:clipboardenabled='true', the content script attaches a custom event listener that routes arbitrary text to the clipboard via the extension's clipboardWrite permission. Any in-page script—including third-party scripts—can dispatch this event with attacker-controlled content, causing the extension to silently overwrite whatever the user last copied.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

cyberark.developerv2.2Chrome Web Store
20Risk
Who publishes it

CyberArk Software Ltd. - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
cyberark.developer
Declared legal entity
CyberArk Software Ltd.
Registered address
9 Hapsagot, PETAH TIKVA 4951041, IL
Registered contact
CyberArk Software Ltd.

Same operator - 1 listing

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Act on the current tab, but only after you click the extension

    activeTab

  • Write to your clipboard

    clipboardWrite

  • Run hidden pages in the background

    offscreen

Updated 30 September 2026ndaciljfdnekbnmcpjidoebejglcjidc