Is Netflix Picture in Picture now for Prime & D+ [QVI] safe?
Netflix Picture in Picture is medium risk. The extension enables "Share anonymous viewing insights" by default, generating a permanent ID unasked. The ID is sent from its Netflix, Prime, Disney+, Hulu code to me3x.online, again to metricsmint.quest, tying both. Not in the listing.
Who publishes itHideApp LLC - 69 other listings from the same operator, 15 of them carrying a finding
HideApp LLC - 69 other listings from the same operator, 15 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
6 other listings published from this account, 42k+ users between them. 1 of them carries a finding.
Same operator - 63 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Persistent tracking ID sent to two undisclosed telemetry domains by default
The extension enables "Share anonymous viewing insights" by default, generating a permanent ID unasked.
The ID is sent from its Netflix, Prime, Disney+, Hulu code to me3x.online, again to metricsmint.quest, tying both.
Not in the listing.
The user installs the extension and later visits a supported streaming site such as netflix.com.
shareInsights was never explicitly turned on; it defaults to true the first time the extension runs.
The extension's page-specific script sends a persistent identifier for the browser to me3x.online, and the same identifier to metricsmint.quest.
Both requests happen automatically on page load, with no prompt or notice shown to the user.
How the persistent ID is created and where it's sent
async function getOrCreateExtensionUserId() {
const stored = await cachedExtensionUserId;
if (stored) return stored;
if (!globalThis.chrome?.storage) return "";
// No stored ID yet: mint one and persist it for future requests.
const id = self.crypto.randomUUID();
await chromeStorageSetKey(EXTENSION_USER_ID_KEY, id);
return (await chromeStorageGetKey(EXTENSION_USER_ID_KEY)) ?? "";
}
// Every logger built from this factory POSTs JSON to the given URL,
// including whatever caller-supplied body (usually the extensionUserId).
function buildHttpLogger(url) {
return (body) => fetch(url, {
method: "POST",
body: JSON.stringify(body),
headers: { "Content-Type": "application/json" },
});
}
const httpLog = buildHttpLogger("https://me3x.online/n/js/dlog");| Content-Type | application/json |
{
"platform": "netflix",
"extVer": "0.2.92",
"namespace": "runOnce",
"extensionUserId": "34862f3b-7046-4056-9e4e-de489054be5c"
}{
"panelist_id": "34862f3b-7046-4056-9e4e-de489054be5c",
"dist": "jkmakgpojigahjdalffbkimpnpabelio",
"language": "en"
}| Field | Value | Why it matters | |
|---|---|---|---|
Persistent browser ID | 34862f3b-7046-4056-9e4e-de489054be5c | A UUID generated once and reused on every request, letting both destinations recognize your browser across visits. | |
Streaming platform | netflix | Which streaming site you were on when the request fired (netflix, primevideo, disneyplus, hulu, etc.). | |
Extension version | 0.2.92 | The installed version of the extension, used to segment the telemetry. | |
Extension ID | jkmakgpojigahjdalffbkimpnpabelio | The extension's Chrome Web Store ID, sent to metricsmint.quest as the dist field. |
- me3x.online
Receives the persistent extensionUserId plus platform and version metadata on every visit to a supported streaming site (POST /n/js/dlog).
- metricsmint.quest
Receives the same UUID as panelist_id (POST /survey), letting activity on this endpoint be tied back to the same browser as me3x.online.