Is GO-Global safe?

Low risk

GO-Global exposes a web-accessible page that any website can use to relay arbitrary parameters, including credentials, to the locally installed GO-Global client via native messaging.

The extension's main.html page is listed as a web-accessible resource with no origin restriction, making it reachable from any website. When loaded, the page reads URL query parameters — including host, username, password, and app arguments — and forwards them verbatim to the com.graphon.goglobal native messaging host, which launches the GO-Global client with those values. Passwords passed this way appear in the URL, in browser history, and in any Referer headers generated by the page.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

GraphOn Corp.v5.0.2.24620Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 5.0.2.24620. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 21 September 2026kkehppgllpkfohejllckommnpfeomhnc