Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeFormApps Extension For Safari
Findings · 2
HIGH FINDINGS · 2
  1. 01Content script on https://*/* exposes a postMessage→native-messaging bridge to every HTTPS page (and iframe), letting any visited site invoke Software602 desktop helpers via attacker-controlled host and XML task payloads.
  2. 02Content script injects a stable detection marker `<div id="wf_fas_extension" data-extversion="...">` into the DOM of any HTTPS page that contains a #wf_fillerform element, exposing extension presence and version to fingerprinting.
OTHER EXTENSIONS

Is FormApps Extension For Safari safe?

High risk

No summary available.

Software602 a.s.v1.1Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.Software602.FormAppsSafariExtension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact