Is Rakuten Drive (Transfer&Cloud) safe?
Rakuten Drive contains a flawed postMessage origin check that lets any window inject file links or modify extension settings in Gmail, Slack, and Chatwork.
The extension adds a file-sharing button to Gmail compose windows, Slack message toolbars, and Chatwork input areas. When clicked, it opens an embedded Rakuten Drive webapp inside an iframe overlay on the page. A logic error in the content script's postMessage handler — using && instead of || — means any window can send messages that insert links into the compose area or toggle the extension's Gmail, Slack, or Chatwork activation settings, without the message origin being validated.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.