Is Microsoft Bing Search for Chrome safe?
Microsoft Bing Search for Chrome fetches remote HTML templates from a Microsoft-controlled URL and injects them into every HTTPS page visited.
Every 240 minutes, the extension retrieves a configuration JSON from go.microsoft.com that supplies a template URL. When any tab finishes loading, the extension fetches that remote URL and writes the returned HTML directly into the page via innerHTML, with no integrity check or Content-Type validation. The extension also sends a persistent machine UUID, OS version, browser version, and current page URL to Microsoft telemetry endpoints on install, on the first Bing search, and in daily pings.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itMicrosoft Corporation - 9 other listings from the same operator, 1 of them carrying a finding
Microsoft Corporation - 9 other listings from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
6 other listings published from this account, 16.3M+ users between them. 1 of them carries a finding.
Same operator - 3 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Daily Telemetry Ping Sends Persistent Machine ID to Microsoft
The extension assigns each device a random ID on install, stored permanently.
Every 24 hours it GETs Microsoft with this ID plus your OS, Chrome version, and channel.
It never rotates, so Microsoft can correlate your device over time.
A 24-hour alarm fires in the background.
The alarm named HKE_PINGALARM is created on install and repeats every 1440 minutes.
The extension sends a GET request to Microsoft containing your device ID, OS, and browser version.
The payload is base64-encoded before being embedded in the URL's UD= query parameter.
The telemetry ping fires once every 24 hours while the browser is open, starting approximately one minute after the alarm is first registered on install.
The telemetry payload is URI-encoded and then base64-encoded before being placed in the UD= query parameter, making it opaque in browser network logs without decoding.
MI=BBDC08F921740CE51A09926E5E89ADC6&LV=1.0.0.19&OS=X11;Linuxx86_64&TE=37&TV=isBG02|pkMicrosoftBingSearchforChrome|tmen-US|bvChrome148.0.0.0|exhkecabaloghleaicfhefejdijblljpco|es2|chorganic|dporganic
| Field | Value | Why it matters | |
|---|---|---|---|
Device ID | BBDC08F921740CE51A09926E5E89ADC6 | A random identifier created on install, stored permanently. Lets Microsoft recognize the same device across sessions and reinstalls. | |
Operating system | X11;Linuxx86_64 | Your OS name and CPU architecture, extracted from the browser's user-agent string. | |
Browser version | Chrome148.0.0.0 | The full Chrome version string running on this device. | |
Extension version | 1.0.0.19 | Which version of this extension is installed. | |
Distribution channel | organic | How the extension was acquired (for example, direct from the web store vs. a bundled install). | |
Market / locale | en-US | Your browser's language and region setting. |
UUID generation and daily telemetry send (scripts/ping.js)
function guid() {
function randomHex4() {
return Math.floor(65536 * (1 + Math.random())).toString(16).substring(1);
}
// 8 groups of 4 hex chars = 32-char UUID (no dashes)
var machineId = randomHex4() + randomHex4() + randomHex4() + randomHex4()
+ randomHex4() + randomHex4() + randomHex4() + randomHex4();
machineId = machineId.toLocaleUpperCase();
chrome.storage.local.set({ [MACHINE_ID]: machineId }); // stored permanently
return machineId;
}function SendPingDetails(pingType) {
var uaStart = navigator.userAgent.indexOf('(');
var uaEnd = navigator.userAgent.indexOf(')');
var osString = navigator.userAgent.substring(uaStart + 1, uaEnd).replace(/\s/g, '');
var extName = manifestData.name.replace(/ /g, '').replace(/&/g, 'and');
var chromeVer = navigator.userAgent.substr(navigator.userAgent.indexOf('Chrome'))
.split(' ')[0].replace('/', '');
chrome.storage.local.get([PARTNER_CODE, CHANNEL, MACHINE_ID, DPC, LP_MARKET, MARKET], (stored) => {
var market = stored[MARKET] ? stored[MARKET] : navigator.language;
var url = 'https://go.microsoft.com/fwlink/?linkid=2243942&';
// Pipe-delimited TV field: partner code, extension name, market, browser version,
// extension ID, ping type, channel, DPC, LP market
var tvParam = 'TV=is' + (stored[PARTNER_CODE] || 'BG02')
+ '|pk' + extName
+ '|tm' + market
+ '|bv' + chromeVer
+ '|ex' + extensionId
+ '|es' + pingType; // 1=install, 2=daily, 3=update
if (stored[CHANNEL]) tvParam += '|ch' + stored[CHANNEL];
if (stored[DPC]) tvParam += '|dp' + stored[DPC];
if (stored[LP_MARKET]) tvParam += '|lm' + stored[LP_MARKET];
var payload = 'MI=' + stored[MACHINE_ID] // persistent device UUID
+ '&LV=' + ExtensionVersion
+ '&OS=' + osString
+ '&TE=37&' // fixed telemetry event type
+ tvParam;
// Encode then base64 before embedding in URL — opaque in network logs
url += 'UD=' + (payload = btoa(encodeURI(payload))) + '&ver=2';
url = encodeURI(url);
fetch(url); // fire-and-forget, no response handling
});
}- go.microsoft.com
Microsoft link-redirect service used as the telemetry ingestion endpoint. Receives the base64-encoded device metadata payload in the UD= query parameter.
Install and First-Search Events POST Machine ID and URL to Microsoft
On install, the extension sends Microsoft a persistent device ID, browser details, OS, and channel.
Your first Bing search fires a POST with the same ID and full search URL, including your query.
Both match the ID from the daily ping.
The extension installs, or the user performs their first Bing search.
Two separate events fire this POST: extension install (eventId=ExtensionInstall) and first Bing search navigation (eventId=ExtensionFSN).
The extension POSTs a JSON payload to Microsoft containing your device ID, browser details, and the current page URL.
On first search, the current URL includes the full Bing search query in the q= parameter.
| Content-Type | application/json; charset=utf-8 |
{
"partnercode": "BG02",
"os": "10",
"mkt": "en-US",
"browser": "Chrome",
"xid": "hkecabaloghleaicfhefejdijblljpco",
"channel": "organic",
"machineid": "BBDC08F921740CE51A09926E5E89ADC6",
"browserVersion": "Chrome148.0.0.0",
"currenturl": "https://www.bing.com/search?EID=MBSC&form=BGGCDF&pc=BG02&q=weather",
"eventId": "ExtensionFSN",
"bcex": "1"
}| Field | Value | Why it matters | |
|---|---|---|---|
Device ID | BBDC08F921740CE51A09926E5E89ADC6 | The persistent UUID from install, also used in the daily ping. Lets Microsoft correlate install, search, and activity to one device. | |
Current URL | https://www.bing.com/search?EID=MBSC&form=BGGCDF&pc=BG02&q=weather | The page URL when the event fires. On first search, this is your Bing search URL, including the query in the q= parameter. | |
Event type | ExtensionFSN | Distinguishes install from first-search events. | |
Operating system | 10 | Your OS version, derived from the browser user-agent string. | |
Browser version | Chrome148.0.0.0 | The full Chrome version string running on this device. | |
Distribution channel | organic | How the extension was acquired. |
getLoadData_InstrumentationTracking(), POST function (scripts/ping.js)
function getLoadData_InstrumentationTracking(
partnerCode, market, extensionId, channel, bcex, machineId, eventId, currentUrl
) {
// Default empty-string fallbacks for optional fields
if (!machineId) machineId = '';
if (!channel) channel = 'Organic';
if (!market) market = '';
if (!bcex) bcex = '';
var payload = {
partnercode: partnerCode,
os: operatingSystemVersion(), // e.g. '10' for Windows 10
mkt: market, // browser locale, e.g. 'en-US'
browser: getBrowserVersion(), // e.g. 'Chrome'
xid: extensionId, // the Chrome extension ID
channel: channel, // distribution channel
machineid: machineId, // persistent UUID from chrome.storage.local
browserVersion: navigator.userAgent.substr(navigator.userAgent.indexOf('Chrome'))
.split(' ')[0].replace('/', ''),
currenturl: currentUrl, // extension URL on install; actual search URL on FSN event
eventId: eventId, // 'ExtensionInstall' or 'ExtensionFSN'
bcex: bcex
};
fetch('https://browserdefaults.microsoft.com/api/hpinst/InstrumentationTracking', {
method: 'POST',
headers: { 'Content-Type': 'application/json; charset=utf-8' },
body: JSON.stringify(payload)
})
.then((res) => { if (res.ok) console.log('Success'); })
.catch(() => {});
}- browserdefaults.microsoft.com
Microsoft's browser-defaults instrumentation service. Receives install and first-search JSON payloads including machine ID and the current page URL.
What it can do
Permissions this extension asks for, as declared in version 1.0.0.19. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every secure site you visit
https://*/*
Read and change your data on every site you visit
http://*/*
Schedule its own background tasks
alarms
Add items to the right-click menu
contextMenus
Read and change cookies, including the ones that keep you signed in
cookies
Block and redirect the requests your browser makes
declarativeNetRequest
Show you desktop notifications
notifications
Run its own code inside the pages you visit
scripting
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Where it sends data
Destinations our analysis observed Microsoft Bing Search for Chrome contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- go.microsoft.com
Microsoft Bing Search for Chrome sends data to go.microsoft.com. 6 other extensions we have analysed send data here.
- browserdefaults.microsoft.com
Microsoft Bing Search for Chrome sends data to browserdefaults.microsoft.com. 2 other extensions we have analysed send data here.