Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeCyberhaven Extension
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01DLP content script on <all_urls> monitors copy/paste/file-upload events and forwards page URL, title, file metadata, and copy/paste actions to the Cyberhaven host app via a localhost HTTP transport on Mac.
  2. 02AI-platform content scripts harvest the logged-in user's email from ChatGPT, Deepseek, Gemini, Perplexity, and Claude pages by reading react-router state, auth0 localStorage tokens, or hooked XHR responses to user-info APIs.
  3. 03Extension transports collected DLP events over plaintext HTTP to localhost on a fixed port set, with protocol fallback (https→http) and port cycling, and the manifest CSP whitelists ten distinct localhost ports for both http and https connect-src.
+2 more findings locked
OTHER EXTENSIONS

Is Cyberhaven Extension safe?

Medium risk

No summary available.

CYBERHAVEN, INCv25.11.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026io.cyberhaven.lightbeam.CyberhavenSafariExtension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact