Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeOceanHero: Save Our Oceans with Every New Tab
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01Extension reads all signed-in Google account names and email addresses from the accounts.google.com ListAccounts API using the 'cookies' permission and the host_permission for accounts.google.com
  2. 02Extension reads the user's top-visited websites (chrome.topSites) and displays them as shortcut tiles on the new tab page, with the top sites list sent to a third-party ad network (bdn11.veve.com) alongside the user ID for ad targeting
  3. 03Extension fetches remote configuration from oceanhero.today/api/remote-config on every NTP load, sending platform, OS, version, experimentId, and installationDate; the returned 'scenario' object controls feature flags that alter the extension's behavior (content ads, banners, shell gain rates, etc.)
+2 more findings locked
OTHER EXTENSIONS

Is OceanHero: Save Our Oceans with Every New Tab safe?

Medium risk

OceanHero reads signed-in Google accounts and top-visited sites, and forwards your user ID to an ad network on every new tab.

OceanHero GmbHv10.7Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026cdbccfkcpkmimlajcjpodelocoeifjhp

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact