Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeCyberArk Identity Browser Extension
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01v26.8.1 adds 7 new extension IDs to externally_connectable and exposes two new onMessageExternal handlers — GET_APPS_FOR_URL (returns enterprise app list + usernames for a given URL) and GET_CREDS (returns decrypted username and password from the CyberArk tenant) — that any of those 7 extensions can invoke without user interaction.
  2. 02Extension disables Chrome's built-in password saving prompt on all sites when handling enterprise-managed credentials
  3. 03Extension retrieves stored plaintext passwords from the CyberArk tenant and injects them into login form fields
+2 more findings locked
OTHER EXTENSIONS

Is CyberArk Identity Browser Extension safe?

Clean risk

No summary available.

cyberark.developerv26.3.2Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026jifcoadedkediabkmjbflemiblmnbjfk

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact