Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeCyberark Identity Extension
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Tenant hostname is auto-discovered from any cookie domain whose root resolves to a CyberArk-recognised alternative tenant domain; resolution is done via Google Public DNS (dns.google) when the sysinfo path fails.
  2. 02Content scripts injected into every http/https frame on every site (all_frames=true) to monitor every form for credential entry, plus a webRequest.onAuthRequired blocking listener registered on <all_urls> for HTTP Basic auth filling.
  3. 03LandCatch / BHAnalyzer behavior tracker watches every form on every site for input changes, clicks, Enter keys, and navigation events; when it detects a login submission, it submits the captured credential to /uprest/CreateDetectedPersonalApp on the configured CyberArk tenant.
+1 more finding locked
OTHER EXTENSIONS

Is Cyberark Identity Extension safe?

Medium risk

No summary available.

CyberArk Software, Incv26.3Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.cyberark.identity.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact