Is Microsoft Bing Search Engine safe?

Medium risk

Microsoft Bing Search Engine reads all browser cookies to find tracking codes and sends browser telemetry to g.ceipmsn.com daily.

On startup and daily thereafter, the extension scans every cookie in the browser's cookie store looking for Microsoft distribution tracking codes ('PCCode' or 'channel'), deletes any it finds, and stores the values locally. It also generates a persistent machine GUID and transmits it alongside OS and browser version details to g.ceipmsn.com via a plain HTTP GET request. This telemetry fires on install, on update, and whenever any other extension is enabled.

Microsoft Corporationv0.0.0.14Chrome Web Store
45Risk
Who publishes it

Microsoft Corporation - 10 other listings from the same operator, 2 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Microsoft Corporation
Declared legal entity
Microsoft Corporation
Registered address
One Microsoft Way, Redmond, WA 98052-8300, US
Registered contact
Microsoft Corporation

Same operator - 3 listings

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

All-domain cookie scan finds Bing partner-code cookies

cookies.getAll({}) with no domain filter returns every browser cookie, not just bing.com/microsoft.com.

Planted PCCode/channel cookies on bing.com were picked up, while url-scoped calls to browserdefaults.microsoft.com found nothing.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install or update the extension, or Chrome re-enables it.

This schedules a one-minute alarm (GAI_BGALARM) that fires once the background service worker loads.

The extension did this

The extension calls chrome.cookies.getAll({}) with no domain filter, then scans every returned cookie for the names PCCode or channel.

This reads cookies from every domain in the browser's cookie jar, not only the bing.com and microsoft.com domains listed in host_permissions.

02EvidenceFIELD TABLE
Values captured by the unscoped cookie scan (reproduced with planted test cookies)
FieldValueWhy it matters
Bing partner code (cookie named PCCode)
PCCode=U558A Microsoft distribution/partner code. The scan reads the value of any cookie literally named PCCode, on any domain, not only Microsoft's.
Distribution channel (channel cookie)
channel=organicRecords which install or promotion channel is credited. The scan reads any cookie literally named channel, on any domain.
Local copy of matched values
chrome.storage.local: {pc: "U558", channel: "organic"}Whatever the scan matches is written into the extension's own storage and reused across the browser session.
03EvidenceCODE COMPARE
The code that does this

Unscoped cookie scan (background.js) and telemetry send (ping.js)

What it actually does
Unscoped cookie scanbackground.js:17-37
chrome.cookies.getAll({}, function (cookies) {

	for (var i in cookies) {
		cookieFound = false;
		if (cookies[i].name == "PCCode") {
			defaultPC = cookies[i].value;
			cookieFound = true;
			details.pc = defaultPC;
		}
		else if (cookies[i].name == "channel") {
			details.channel = cookies[i].value;
			cookieFound = true;
		}
		//Remove cookies value
		if (cookieFound) {
			var url = "http" + (cookies[i].secure ? "s" : "") + "://" + cookies[i].domain + cookies[i].path;
			chrome.cookies.remove({ "url": url, "name": cookies[i].name });
		}
	}
	chrome.storage.local.set(details, () => { resolve(details) });
});
Telemetry ping carrying the stored valuesping.js:230-258
function SendPingDetails(status, pc, channel, dpc, machineId) {
    var startIndex = navigator.userAgent.indexOf("(");
    var endIndex = navigator.userAgent.indexOf(")");
    var OS = navigator.userAgent.substring(startIndex + 1, endIndex).replace(/\s/g, '');
    var browserLanguage = navigator.language;

    var manifestData = chrome.runtime.getManifest();
    var ExtensionVersion = manifestData.version;

    var ExtensionName = manifestData.name.replace(/ /g, "").replace(/&/g, 'and');
    var ExtensionId = chrome.runtime.id;

    var BrowserVersion = navigator.userAgent.substr(navigator.userAgent.indexOf("Chrome")).split(" ")[0].replace("/", "");

    var _pc = !pc ? defaultPC : pc;
    var pingURL = 'http://g.ceipmsn.com/8SE/44?';
    var tVData = 'TV=is' + _pc + '|pk' + ExtensionName + '|tm' + browserLanguage + '|bv' + BrowserVersion + '|ex' + ExtensionId + '|es' + status;
    if (channel)
        tVData = tVData + "|ch" + channel;
    if (dpc)
        tVData = tVData + "|dp" + dpc;
    pingURL = pingURL + 'MI=' + machineId + '&LV=' + ExtensionVersion + '&OS=' + OS + '&TE=37&' + tVData;
    pingURL = encodeURI(pingURL);

    fetch(pingURL);
};
04EvidenceNETWORK CAPTURE
Captured request
GEThttp://g.ceipmsn.com/8SE/44?MI=8F3A1C2D9B7E4F60ABCD1234EF567890&LV=0.0.0.14&OS=WindowsNT10.0;Win64;x64&TE=37&TV=isU558|pkMicrosoftBingSearchEngine|tmen-US|bv138.0.0.0|exgaialadjjkjjkdhfmehfgmgkoeniabam|es1|chorganic|dpU558_organic
Not captured; this request was not observed firing during dynamic analysis. The URL and parameter mapping (MI=machine ID, TV=is<pc>|pk<name>|tm<lang>|bv<browser>|ex<extension id>|es<status>, optional |ch<channel>|dp<dpc>) come directly from the shipped SendPingDetails() function; the query values shown here are illustrative, built from that mapping rather than a live capture.
05EvidenceTHIRD PARTY LIST
Where the scanned cookie values end up, per shipped code
  • g.ceipmsn.com

    Microsoft telemetry endpoint. Receives stored pc/channel values plus a random machine ID, extension ID, browser version, OS and locale over plain HTTP.

What it can do

Permissions this extension asks for, as declared in version 0.0.0.14. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on bing.com

    http://*.bing.com/* and 1 more

  • Read and change your data on microsoft.com

    https://*.microsoft.com/*

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • See, disable and uninstall your other extensions, including your security ones

    management

  • Store data in your browser

    storage

  • Schedule its own background tasks

    alarms

  • Run its own code inside the pages you visit

    scripting

Where it sends data

Destinations our analysis observed Microsoft Bing Search Engine contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • g.ceipmsn.com

    Microsoft Bing Search Engine sends data to g.ceipmsn.com. 9 other extensions we have analysed send data here.

Updated 30 September 2026gaialadjjkjjkdhfmehfgmgkoeniabam