Is Microsoft Bing Search Engine safe?
Microsoft Bing Search Engine reads all browser cookies to find tracking codes and sends browser telemetry to g.ceipmsn.com daily.
On startup and daily thereafter, the extension scans every cookie in the browser's cookie store looking for Microsoft distribution tracking codes ('PCCode' or 'channel'), deletes any it finds, and stores the values locally. It also generates a persistent machine GUID and transmits it alongside OS and browser version details to g.ceipmsn.com via a plain HTTP GET request. This telemetry fires on install, on update, and whenever any other extension is enabled.
Who publishes itMicrosoft Corporation - 10 other listings from the same operator, 2 of them carrying a finding
Microsoft Corporation - 10 other listings from the same operator, 2 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
7 other listings published from this account, 4.3M+ users between them. 2 of them carry a finding.
Same operator - 3 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
All-domain cookie scan finds Bing partner-code cookies
cookies.getAll({}) with no domain filter returns every browser cookie, not just bing.com/microsoft.com.
Planted PCCode/channel cookies on bing.com were picked up, while url-scoped calls to browserdefaults.microsoft.com found nothing.
You install or update the extension, or Chrome re-enables it.
This schedules a one-minute alarm (GAI_BGALARM) that fires once the background service worker loads.
The extension calls chrome.cookies.getAll({}) with no domain filter, then scans every returned cookie for the names PCCode or channel.
This reads cookies from every domain in the browser's cookie jar, not only the bing.com and microsoft.com domains listed in host_permissions.
| Field | Value | Why it matters | |
|---|---|---|---|
Bing partner code (cookie named PCCode) | PCCode=U558 | A Microsoft distribution/partner code. The scan reads the value of any cookie literally named PCCode, on any domain, not only Microsoft's. | |
Distribution channel (channel cookie) | channel=organic | Records which install or promotion channel is credited. The scan reads any cookie literally named channel, on any domain. | |
Local copy of matched values | chrome.storage.local: {pc: "U558", channel: "organic"} | Whatever the scan matches is written into the extension's own storage and reused across the browser session. |
Unscoped cookie scan (background.js) and telemetry send (ping.js)
chrome.cookies.getAll({}, function (cookies) {
for (var i in cookies) {
cookieFound = false;
if (cookies[i].name == "PCCode") {
defaultPC = cookies[i].value;
cookieFound = true;
details.pc = defaultPC;
}
else if (cookies[i].name == "channel") {
details.channel = cookies[i].value;
cookieFound = true;
}
//Remove cookies value
if (cookieFound) {
var url = "http" + (cookies[i].secure ? "s" : "") + "://" + cookies[i].domain + cookies[i].path;
chrome.cookies.remove({ "url": url, "name": cookies[i].name });
}
}
chrome.storage.local.set(details, () => { resolve(details) });
});function SendPingDetails(status, pc, channel, dpc, machineId) {
var startIndex = navigator.userAgent.indexOf("(");
var endIndex = navigator.userAgent.indexOf(")");
var OS = navigator.userAgent.substring(startIndex + 1, endIndex).replace(/\s/g, '');
var browserLanguage = navigator.language;
var manifestData = chrome.runtime.getManifest();
var ExtensionVersion = manifestData.version;
var ExtensionName = manifestData.name.replace(/ /g, "").replace(/&/g, 'and');
var ExtensionId = chrome.runtime.id;
var BrowserVersion = navigator.userAgent.substr(navigator.userAgent.indexOf("Chrome")).split(" ")[0].replace("/", "");
var _pc = !pc ? defaultPC : pc;
var pingURL = 'http://g.ceipmsn.com/8SE/44?';
var tVData = 'TV=is' + _pc + '|pk' + ExtensionName + '|tm' + browserLanguage + '|bv' + BrowserVersion + '|ex' + ExtensionId + '|es' + status;
if (channel)
tVData = tVData + "|ch" + channel;
if (dpc)
tVData = tVData + "|dp" + dpc;
pingURL = pingURL + 'MI=' + machineId + '&LV=' + ExtensionVersion + '&OS=' + OS + '&TE=37&' + tVData;
pingURL = encodeURI(pingURL);
fetch(pingURL);
};- g.ceipmsn.com
Microsoft telemetry endpoint. Receives stored pc/channel values plus a random machine ID, extension ID, browser version, OS and locale over plain HTTP.
What it can do
Permissions this extension asks for, as declared in version 0.0.0.14. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on bing.com
http://*.bing.com/* and 1 more
Read and change your data on microsoft.com
https://*.microsoft.com/*
Read and change cookies, including the ones that keep you signed in
cookies
See, disable and uninstall your other extensions, including your security ones
management
Store data in your browser
storage
Schedule its own background tasks
alarms
Run its own code inside the pages you visit
scripting
Where it sends data
Destinations our analysis observed Microsoft Bing Search Engine contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- g.ceipmsn.com
Microsoft Bing Search Engine sends data to g.ceipmsn.com. 9 other extensions we have analysed send data here.