Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeFrame.io - Video Collaboration
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Hardcoded Segment writeKey ships in the FCP extension binary; the bundled Segment SDK sends usage telemetry to a third-party analytics vendor (api.segment.io) in addition to the disclosed api.frame.io traffic.
  2. 02Final Cut Pro Workflow Extension reads the active FCP library/timeline via Apple Events and uploads project data to api.frame.io (vendor backend).
  3. 03FCP extension ships with com.apple.security.cs.disable-library-validation entitlement, weakening the hardened-runtime guarantee that only same-team-signed dynamic libraries can be loaded into the extension process.
OTHER EXTENSIONS

Is Frame.io - Video Collaboration safe?

Medium risk

No summary available.

Frame.iov2.7.6Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.frameio.frameio.frameio-fcpx

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact