Is Save to Facebook safe?

High risk

Save to Facebook is high risk. Every browser start, Save to Facebook fetches a JavaScript file from Facebook servers and runs it with full extension privileges. There is no integrity check; Facebook can change what runs any time, with no notice or consent.

75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-829
SourceAI SANDBOX

Executes Unverified Remote JS From Facebook on Every Load

Every browser start, Save to Facebook fetches a JavaScript file from Facebook servers and runs it with full extension privileges.

There is no integrity check; Facebook can change what runs any time, with no notice or consent.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension or your browser starts with it enabled.

The extension did this

The extension fetches a JavaScript file from Facebook servers and executes it with full extension privileges, no integrity check, no user notice.

The downloaded code runs in the background page with access to chrome.cookies, chrome.tabs, and any other API the extension holds.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://www.facebook.com/saved/extension/rsrc/js/?key=a1b2c3d4-e5f6-7890-abcd-ef1234567890
HTTP 200 application/javascript, arbitrary JS served by Facebook; content changes at Facebook's discretion without any version pin or hash check in the extension.
Headers
Originchrome-extension://jmfikkaogpplgnfjmbjdpalkhclendgd
Sec-Fetch-Destscript
Sec-Fetch-Modecors
03EvidenceCODE COMPARE
The code that does this

The code that fetches and executes the remote script.

What it actually does
What the code does in plain English
// On every background page load, the extension:
// 1. Generates a new random GUID (cache-buster)
// 2. Injects a <script src="https://www.facebook.com/saved/extension/rsrc/js/?key=GUID">
//    directly into the background page DOM
// 3. The crossOrigin='anonymous' attribute lets the request succeed cross-origin,
//    but there is NO integrity= attribute — no SHA hash to verify the content
// 4. Whatever JavaScript Facebook returns is executed immediately with
//    the full permissions of the extension (cookies, tabs, activeTab, etc.)
//
// Because the GUID is random every time, the browser cache is bypassed
// and a fresh network request is always made to Facebook servers.
//
// After successful load, the extension reloads itself every 24 hours
// (window.setTimeout(chrome.runtime.reload, 24 * 60 * 60000))
// ensuring fresh remote code is fetched daily even if the background stays alive.
04EvidencePLAIN NOTE
Why This Matters

The extension holds `cookies` permission scoped to `https://*.facebook.com/*`. Code fetched from Facebook runs in the same background page context and therefore has access to those cookies — your Facebook session tokens. Facebook can update what this code does at any time, without shipping a new extension version through the Chrome Web Store review process, and without any notification to the user.

05EvidenceTHIRD PARTY LIST
Where the remote code comes from:
  • www.facebook.com

    Serves the JavaScript bundle that runs inside the extension. Facebook (Meta) controls this endpoint and can change the code at any time.

  • staticxx.facebook.com

    Facebook CDN endpoint; may serve subsidiary JS or CSS assets loaded by the fetched bundle (referenced in CSP allowlist via *.fbcdn.net and *.facebook.com).

06EvidenceARTIFACT
Check if you're affected

Intercepts the dynamic script injection in the Save to Facebook background page and logs the fetched URL and the first 200 bytes of the response body, proving that remote code is fetched and executed without any integrity check.

RequiresChrome with Developer mode enabled
save-to-facebook-sri-check.js · js
// save-to-facebook-sri-check.js
// Run in DevTools on the Save to Facebook background page
// (chrome://extensions → Save to Facebook → background page link)
// Hooks createElement to intercept the remote script injection.

(function() {
  const origCreateElement = document.createElement.bind(document);
  document.createElement = function(tag) {
    const el = origCreateElement(tag);
    if (tag.toLowerCase() === 'script') {
      Object.defineProperty(el, 'src', {
        set(value) {
          if (value && value.includes('facebook.com')) {
            console.warn('[SRI-CHECK] Remote script injected WITHOUT integrity check:', value);
            console.warn('[SRI-CHECK] integrity attribute:', el.integrity || '(none — no SRI)');
            // Fetch the URL ourselves to peek at first bytes
            fetch(value, {credentials: 'omit'})
              .then(r => r.text())
              .then(t => console.warn('[SRI-CHECK] First 200 chars of fetched code:', t.slice(0, 200)))
              .catch(e => console.warn('[SRI-CHECK] fetch failed:', e));
          }
          el.setAttribute('src', value);
        },
        get() { return el.getAttribute('src'); }
      });
    }
    return el;
  };
  console.log('[SRI-CHECK] Installed. Reload the background page to see the remote script fetch.');
})();
How to run it
  1. 1
    Go to chrome://extensions, enable Developer mode.
  2. 2
    Click 'Save to Facebook' > 'background page' for DevTools.
  3. 3
    Paste this script in Console, Enter.
  4. 4
    Ctrl+R or chrome.runtime.reload().
  5. 5
    Watch for [SRI-CHECK] messages.

What it can do

Permissions this extension asks for, as declared in version 2.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on facebook.com

    https://*.facebook.com/*

  • Act on the current tab, but only after you click the extension

    activeTab

  • Read and change cookies, including the ones that keep you signed in

    cookies

Updated 21 September 2026jmfikkaogpplgnfjmbjdpalkhclendgd