Is Microsoft Bing Search for Chrome safe?

Medium risk

Microsoft Bing Search for Chrome fetches remote HTML templates from a Microsoft-controlled URL and injects them into every HTTPS page visited.

Every 240 minutes, the extension retrieves a configuration JSON from go.microsoft.com that supplies a template URL. When any tab finishes loading, the extension fetches that remote URL and writes the returned HTML directly into the page via innerHTML, with no integrity check or Content-Type validation. The extension also sends a persistent machine UUID, OS version, browser version, and current page URL to Microsoft telemetry endpoints on install, on the first Bing search, and in daily pings.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Microsoft Corporationv1.0.0.19Chrome Web Store
45Risk
Who publishes it

Microsoft Corporation - 9 other listings from the same operator, 1 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Microsoft Corporation
Declared legal entity
Microsoft Corporation
Registered address
One Microsoft Way, Redmond, WA 98052-8300, US
Registered contact
Microsoft Corporation

Same operator - 3 listings

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

browserdefaults.chinacloudsites.cn
Also called by 2 other listings: Microsoft Bing Search with Rewards, Bing Search

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityLOW
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Daily Telemetry Ping Sends Persistent Machine ID to Microsoft

The extension assigns each device a random ID on install, stored permanently.

Every 24 hours it GETs Microsoft with this ID plus your OS, Chrome version, and channel.

It never rotates, so Microsoft can correlate your device over time.

01EvidenceCAUSE EFFECT
What actually happens
You did this

A 24-hour alarm fires in the background.

The alarm named HKE_PINGALARM is created on install and repeats every 1440 minutes.

The extension did this

The extension sends a GET request to Microsoft containing your device ID, OS, and browser version.

The payload is base64-encoded before being embedded in the URL's UD= query parameter.

02EvidenceTEMPORAL PATTERN
When this fires
Every 1 day

The telemetry ping fires once every 24 hours while the browser is open, starting approximately one minute after the alarm is first registered on install.

03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

The telemetry payload is URI-encoded and then base64-encoded before being placed in the UD= query parameter, making it opaque in browser network logs without decoding.

What's actually being sent
MI=BBDC08F921740CE51A09926E5E89ADC6&LV=1.0.0.19&OS=X11;Linuxx86_64&TE=37&TV=isBG02|pkMicrosoftBingSearchforChrome|tmen-US|bvChrome148.0.0.0|exhkecabaloghleaicfhefejdijblljpco|es2|chorganic|dporganic
04EvidenceFIELD TABLE
Fields decoded from the UD= payload (observed during dynamic analysis)
FieldValueWhy it matters
Device ID
BBDC08F921740CE51A09926E5E89ADC6A random identifier created on install, stored permanently. Lets Microsoft recognize the same device across sessions and reinstalls.
Operating system
X11;Linuxx86_64Your OS name and CPU architecture, extracted from the browser's user-agent string.
Browser version
Chrome148.0.0.0The full Chrome version string running on this device.
Extension version
1.0.0.19Which version of this extension is installed.
Distribution channel
organicHow the extension was acquired (for example, direct from the web store vs. a bundled install).
Market / locale
en-USYour browser's language and region setting.
05EvidenceCODE COMPARE
The code that does this

UUID generation and daily telemetry send (scripts/ping.js)

What it actually does
guid() — generates the persistent device identifier on installscripts/ping.js
function guid() {
  function randomHex4() {
    return Math.floor(65536 * (1 + Math.random())).toString(16).substring(1);
  }
  // 8 groups of 4 hex chars = 32-char UUID (no dashes)
  var machineId = randomHex4() + randomHex4() + randomHex4() + randomHex4()
                + randomHex4() + randomHex4() + randomHex4() + randomHex4();
  machineId = machineId.toLocaleUpperCase();
  chrome.storage.local.set({ [MACHINE_ID]: machineId }); // stored permanently
  return machineId;
}
SendPingDetails() — assembles and sends the daily pingscripts/ping.js
function SendPingDetails(pingType) {
  var uaStart = navigator.userAgent.indexOf('(');
  var uaEnd   = navigator.userAgent.indexOf(')');
  var osString  = navigator.userAgent.substring(uaStart + 1, uaEnd).replace(/\s/g, '');
  var extName   = manifestData.name.replace(/ /g, '').replace(/&/g, 'and');
  var chromeVer = navigator.userAgent.substr(navigator.userAgent.indexOf('Chrome'))
                    .split(' ')[0].replace('/', '');

  chrome.storage.local.get([PARTNER_CODE, CHANNEL, MACHINE_ID, DPC, LP_MARKET, MARKET], (stored) => {
    var market = stored[MARKET] ? stored[MARKET] : navigator.language;
    var url    = 'https://go.microsoft.com/fwlink/?linkid=2243942&';

    // Pipe-delimited TV field: partner code, extension name, market, browser version,
    // extension ID, ping type, channel, DPC, LP market
    var tvParam = 'TV=is' + (stored[PARTNER_CODE] || 'BG02')
                + '|pk' + extName
                + '|tm' + market
                + '|bv' + chromeVer
                + '|ex' + extensionId
                + '|es' + pingType;     // 1=install, 2=daily, 3=update
    if (stored[CHANNEL])   tvParam += '|ch' + stored[CHANNEL];
    if (stored[DPC])       tvParam += '|dp' + stored[DPC];
    if (stored[LP_MARKET]) tvParam += '|lm' + stored[LP_MARKET];

    var payload = 'MI=' + stored[MACHINE_ID]    // persistent device UUID
                + '&LV=' + ExtensionVersion
                + '&OS=' + osString
                + '&TE=37&'                      // fixed telemetry event type
                + tvParam;

    // Encode then base64 before embedding in URL — opaque in network logs
    url += 'UD=' + (payload = btoa(encodeURI(payload))) + '&ver=2';
    url = encodeURI(url);
    fetch(url);  // fire-and-forget, no response handling
  });
}
06EvidenceTHIRD PARTY LIST
Destination for daily telemetry pings
  • go.microsoft.com

    Microsoft link-redirect service used as the telemetry ingestion endpoint. Receives the base64-encoded device metadata payload in the UD= query parameter.

SeverityLOW
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Install and First-Search Events POST Machine ID and URL to Microsoft

On install, the extension sends Microsoft a persistent device ID, browser details, OS, and channel.

Your first Bing search fires a POST with the same ID and full search URL, including your query.

Both match the ID from the daily ping.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The extension installs, or the user performs their first Bing search.

Two separate events fire this POST: extension install (eventId=ExtensionInstall) and first Bing search navigation (eventId=ExtensionFSN).

The extension did this

The extension POSTs a JSON payload to Microsoft containing your device ID, browser details, and the current page URL.

On first search, the current URL includes the full Bing search query in the q= parameter.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://browserdefaults.microsoft.com/api/hpinst/InstrumentationTracking
HTTP 200 OK
Headers
Content-Typeapplication/json; charset=utf-8
Body
{
  "partnercode": "BG02",
  "os": "10",
  "mkt": "en-US",
  "browser": "Chrome",
  "xid": "hkecabaloghleaicfhefejdijblljpco",
  "channel": "organic",
  "machineid": "BBDC08F921740CE51A09926E5E89ADC6",
  "browserVersion": "Chrome148.0.0.0",
  "currenturl": "https://www.bing.com/search?EID=MBSC&form=BGGCDF&pc=BG02&q=weather",
  "eventId": "ExtensionFSN",
  "bcex": "1"
}
03EvidenceFIELD TABLE
JSON POST body fields (observed during dynamic analysis)
FieldValueWhy it matters
Device ID
BBDC08F921740CE51A09926E5E89ADC6The persistent UUID from install, also used in the daily ping. Lets Microsoft correlate install, search, and activity to one device.
Current URL
https://www.bing.com/search?EID=MBSC&form=BGGCDF&pc=BG02&q=weatherThe page URL when the event fires. On first search, this is your Bing search URL, including the query in the q= parameter.
Event type
ExtensionFSNDistinguishes install from first-search events.
Operating system
10Your OS version, derived from the browser user-agent string.
Browser version
Chrome148.0.0.0The full Chrome version string running on this device.
Distribution channel
organicHow the extension was acquired.
04EvidenceCODE COMPARE
The code that does this

getLoadData_InstrumentationTracking(), POST function (scripts/ping.js)

What it actually does
function getLoadData_InstrumentationTracking(
  partnerCode, market, extensionId, channel, bcex, machineId, eventId, currentUrl
) {
  // Default empty-string fallbacks for optional fields
  if (!machineId) machineId = '';
  if (!channel)   channel   = 'Organic';
  if (!market)    market    = '';
  if (!bcex)      bcex      = '';

  var payload = {
    partnercode:    partnerCode,
    os:             operatingSystemVersion(),   // e.g. '10' for Windows 10
    mkt:            market,                     // browser locale, e.g. 'en-US'
    browser:        getBrowserVersion(),         // e.g. 'Chrome'
    xid:            extensionId,                // the Chrome extension ID
    channel:        channel,                    // distribution channel
    machineid:      machineId,                  // persistent UUID from chrome.storage.local
    browserVersion: navigator.userAgent.substr(navigator.userAgent.indexOf('Chrome'))
                      .split(' ')[0].replace('/', ''),
    currenturl:     currentUrl,  // extension URL on install; actual search URL on FSN event
    eventId:        eventId,     // 'ExtensionInstall' or 'ExtensionFSN'
    bcex:           bcex
  };

  fetch('https://browserdefaults.microsoft.com/api/hpinst/InstrumentationTracking', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json; charset=utf-8' },
    body: JSON.stringify(payload)
  })
  .then((res) => { if (res.ok) console.log('Success'); })
  .catch(() => {});
}
05EvidenceTHIRD PARTY LIST
Destination for install and first-search events
  • browserdefaults.microsoft.com

    Microsoft's browser-defaults instrumentation service. Receives install and first-search JSON payloads including machine ID and the current page URL.

What it can do

Permissions this extension asks for, as declared in version 1.0.0.19. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every secure site you visit

    https://*/*

  • Read and change your data on every site you visit

    http://*/*

  • Schedule its own background tasks

    alarms

  • Add items to the right-click menu

    contextMenus

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Show you desktop notifications

    notifications

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Where it sends data

Destinations our analysis observed Microsoft Bing Search for Chrome contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • go.microsoft.com

    Microsoft Bing Search for Chrome sends data to go.microsoft.com. 6 other extensions we have analysed send data here.

  • browserdefaults.microsoft.com

    Microsoft Bing Search for Chrome sends data to browserdefaults.microsoft.com. 2 other extensions we have analysed send data here.

Updated 30 September 2026hkecabaloghleaicfhefejdijblljpco