Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeEleos Health EHR Extension
Findings · 3
HIGH FINDINGS · 3
  1. 01Dual-channel audio capture of telehealth sessions (therapist mic + browser tab audio) uploaded to api.eleos.health via S3 presigned URLs
  2. 02DOM scraping of EHR pages sends full HTML (including patient note fields) to ai-note-mapper-dev.internal.eleos.health when ai-note-mapper-live feature flag is enabled
  3. 03Unleash feature flag client key hardcoded in extension bundle, allowing any party to query the production feature flag API
OTHER EXTENSIONS

Is Eleos Health EHR Extension safe?

Medium risk

No summary available.

chrome_extensionv9.0.6Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026djdnhagbhhcjdbcinfikglnaghcgjkjp

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact