Is Goldfire Highlighting safe?
Goldfire Highlighting allows any web page to collect cookies for arbitrary domains and forward them to a native host application.
The extension's content script runs on all pages and accepts postMessage requests that supply a URL parameter. It relays that URL to the background service worker, which calls chrome.cookies.getAll with the caller-supplied URL without validating that it matches the current page's origin. The collected cookies are then sent to the native application com.ihs.imfind.host via a native messaging connection.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itGoldfire Engineering - no other listings under this identity
Goldfire Engineering - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 10.5.502.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Run its own code inside the pages you visit
scripting
Read and change cookies, including the ones that keep you signed in
cookies
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed Goldfire Highlighting contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.ihs.imfind.host
Goldfire Highlighting sends data to com.ihs.imfind.host. No other extension we have analysed sends data here.