Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomePreMiD
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Developer mode WebSocket backdoor in production code allows arbitrary presence code injection from localhost:3021
  2. 02Two postMessage handlers lack origin validation allowing untrusted pages to manipulate Disney+ presence and Sentry error reporting
  3. 03New RemoteConfigService fetches server-controlled configuration that can remotely adjust heartbeat interval, OAuth retry timing, WebSocket reconnect delays, and Unleash feature-flag polling frequency
+1 more finding locked
OTHER EXTENSIONS

Is PreMiD safe?

Medium risk

No summary available.

Recodivev2.12.5Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026agjnjboanicjcpenljmaaigopkgdnihi

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact