Is Kaspersky Protection 19.0 safe?
Kaspersky Protection 19.0 forwards all HTTPS request headers, password hashes, and full page DOM to the locally installed Kaspersky product.
The extension intercepts every HTTPS request across all browser tabs and sends the full request headers — including Cookie and Authorization values — to a local Kaspersky service. On pages with password fields, it computes an MD5 hash of each typed password and transmits it along with the form URL, and also sends the full page HTML to allow the local product to identify credential fields. Additionally, the local Kaspersky product can instruct the extension to read or set cookies for any URL, and can uninstall other Chrome extensions.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 20.0.543.1521. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
See, disable and uninstall your other extensions, including your security ones
management
Add items to the right-click menu
contextMenus
Read and change cookies, including the ones that keep you signed in
cookies
Watch every request your browser makes
webRequest
Watch, block and rewrite every request your browser makes
webRequestBlocking
Store data in your browser
storage
Where it sends data
Destinations our analysis observed Kaspersky Protection 19.0 contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- gc.kis.v2.scr.kaspersky-labs.com
Kaspersky Protection 19.0 sends data to gc.kis.v2.scr.kaspersky-labs.com. One other extension we have analysed sends data here.