Is Grok AI safe?

Medium risk

Grok AI is medium risk. When the page-content feature is used after permission is granted, Grok AI collects the active page URL, title, and visible text. That page content is forwarded through its iframe messaging flow to grok-ai.easytool.dev.…

52Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Grok AI sends page URL, title, and visible text to easytool.dev.

When the page-content feature is used after permission is granted, Grok AI collects the active page URL, title, and visible text.

That page content is forwarded through its iframe messaging flow to grok-ai.easytool.dev.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-200
Source
Dynamic sandbox
What actually happens
You did this

The user takes the required action for the page-content feature.

The extension did this

The extension extracts the active page URL, title, and visible text, then forwards them to the easytool.dev iframe.

Captured request
POSTgrok-ai.easytool.dev
Fields in the request
  • Active page URL
    https://example.com/article (illustrative)

    Shows the exact page open in the active browser tab.

  • Page title
    Example Article Title (illustrative)

    Provides context about the page being viewed.

  • Visible page text
    Visible paragraph text from the current page (illustrative)

    Includes readable text from the page, which may contain sensitive page content.

Observation

Dynamic analysis confirmed the code path from page-content request to iframe forwarding; an earlier run could not complete the interaction while grok-ai.easytool.dev returned an unavailable-service response.

Grok AI's chat interface runs on easytool.dev, not X.ai or Grok.

Grok AI is branded after xAI's Grok, but every surface loads from an iframe at grok-ai.easytool.dev, unrelated to X.ai.

The code ships a map of five sibling easytool.dev subdomains for other brands.

Testing saw only that domain, never x.ai.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-829
Source
Dynamic sandbox
What actually happens
You did this

The user installs the extension expecting AI chat branded as Grok.

The extension did this

The extension routes the welcome page, side panel, and full-screen chat through an iframe pointed at grok-ai.easytool.dev, a domain not owned by X.ai or Grok.

The code that does this

Hardcoded product map resolving 'grok-ai' to the easytool.dev iframe

Readable version
const p = {    "chatgpt-5": {      name: "chatgpt-5",      iframeUrl: "https://chatgpt-5.easytool.dev"    },    "grok-ai": {      name: "grok-ai",      iframeUrl: "https://grok-ai.easytool.dev"    },    "grok-4": {      name: "grok-4",      iframeUrl: "https://grok-3.easytool.dev"    },    "deepseek-ai": {      name: "deepseek-ai",      iframeUrl: "https://deepseek-ai.easytool.dev"    },    "perplexity-ai": {      name: "perplexity-ai",      iframeUrl: "https://perplexity-ai.easytool.dev"    },    "gemini-2": {      name: "gemini-2",      iframeUrl: "https://gemini-2.easytool.dev"    }  },  i = (e => {    const t = p[e];    if (!t) throw new Error(`Unknown product: ${e}. Available products: ${Object.keys(p).join(", ")}`);    return {      name: t.name,      iframeUrl: t.iframeUrl,      buildDir: `build/${t.name}`    }  })("grok-ai").iframeUrl,  S = {    iframeUrls: {      welcomePage: i + "/welcome-page?ref=ext",      sidepanelPage: i + "/en/new-chat?ref=ext&sidepanel=true",      chatPage: i + "/en/new-chat?ref=ext&fullscreen=true"    },    uninstallUrl: i + "/uninstall-page?ref=ext&d=" + new Date().getTime(),    trustedOrigin: new URL(i).origin,    blockedProtocols: ["chrome:", "edge:", "about:", "devtools:", "chrome-extension:", "chrome-error:", "moz-extension:", "view-source:", "data:", "file:"],    blockedHosts: ["chrome.google.com"]  },
Captured request
GEThttps://grok-ai.easytool.dev/en/new-chat?ref=ext&sidepanel=true

Observed during dynamic analysis: opening the side panel and the welcome page both loaded a cross-origin iframe from grok-ai.easytool.dev. No request in the session reached x.ai, grok.com, or api.openai.com.

Other easytool.dev subdomains hardcoded in the same product map
    • grok-ai.easytool.dev

    Active build for this extension (named 'Grok AI'). Not owned by X.ai.

    • chatgpt-5.easytool.dev

    Configured for a ChatGPT-branded build using the same product map. Not owned by OpenAI.

    • grok-3.easytool.dev

    Configured for a build labeled 'grok-4' internally. Not owned by X.ai.

    • deepseek-ai.easytool.dev

    Configured for a DeepSeek-branded build. Not owned by DeepSeek.

    • perplexity-ai.easytool.dev

    Configured for a Perplexity-branded build. Not owned by Perplexity AI.

    • gemini-2.easytool.dev

    Configured for a Gemini-branded build. Not owned by Google.

Grok AI iframe can request page content and extension storage.

Grok AI trusts messages from grok-ai.easytool.dev, so content from that origin can ask it to extract the page URL, title, and DOM text.

The bridge can also get or set chrome.storage.local values without a consent prompt.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-940
Source
Dynamic sandbox
What actually happens
You did this

The user installs the extension.

The extension did this

The extension trusts messages from grok-ai.easytool.dev and can process requests for page content or chrome.storage.local access.

Captured request
POSThttps://grok-ai.easytool.dev
Fields available through the message bridge
  • Current page URL
    https://example.com/article (illustrative)

    Shows which page the user is viewing when the request runs.

  • Page title
    Example Article Title (illustrative)

    Provides readable context about the active page.

  • DOM content
    Visible article text from the page (illustrative)

    Can include visible text from the active page, including page-specific details.

  • Extension storage data
    savedPreference=true (illustrative)

    Can include values saved by the extension in chrome.storage.local.

Observation

Dynamic analysis confirmed that the trusted-origin message handler routes page-content and storage requests to page extraction and chrome.storage.local handlers.

What it can do

Permissions this extension asks for, as declared in version 3.1.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • Show a panel beside the page

    sidePanel

Updated 30 September 2026hafhkoalnlpoifpidohfjlmeemfifndi