Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeiTab新标签页
Findings · 3
+6 more findings locked
HIGH FINDINGS · 3
  1. 01storage.html exposes the extension's localStorage (including auth token) to any web origin via an unauthenticated postMessage handler, combined with web_accessible_resources making it embeddable from <all_urls>
  2. 02Cloud sync uploads user configuration including bookmarks, todo items, notes, and stocks to developer server when user is logged in
  3. 03Transmits visitor fingerprint ID, city, and random token to developer server on every new tab open; server returns modified search engine affiliate URLs
+6 more findings locked
OTHER EXTENSIONS

Is iTab新标签页 safe?

High risk

No summary available.

xdlumiav1.6.36Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+6 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026mhloojimgilafopcmlcikiidgbbnelip

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact