Is Save to Facebook safe?
Save to Facebook is high risk. Every browser start, Save to Facebook fetches a JavaScript file from Facebook servers and runs it with full extension privileges. There is no integrity check; Facebook can change what runs any time, with no notice or consent.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Executes Unverified Remote JS From Facebook on Every Load
Every browser start, Save to Facebook fetches a JavaScript file from Facebook servers and runs it with full extension privileges.
There is no integrity check; Facebook can change what runs any time, with no notice or consent.
You install the extension or your browser starts with it enabled.
The extension fetches a JavaScript file from Facebook servers and executes it with full extension privileges, no integrity check, no user notice.
The downloaded code runs in the background page with access to chrome.cookies, chrome.tabs, and any other API the extension holds.
| Origin | chrome-extension://jmfikkaogpplgnfjmbjdpalkhclendgd |
| Sec-Fetch-Dest | script |
| Sec-Fetch-Mode | cors |
The code that fetches and executes the remote script.
// On every background page load, the extension: // 1. Generates a new random GUID (cache-buster) // 2. Injects a <script src="https://www.facebook.com/saved/extension/rsrc/js/?key=GUID"> // directly into the background page DOM // 3. The crossOrigin='anonymous' attribute lets the request succeed cross-origin, // but there is NO integrity= attribute — no SHA hash to verify the content // 4. Whatever JavaScript Facebook returns is executed immediately with // the full permissions of the extension (cookies, tabs, activeTab, etc.) // // Because the GUID is random every time, the browser cache is bypassed // and a fresh network request is always made to Facebook servers. // // After successful load, the extension reloads itself every 24 hours // (window.setTimeout(chrome.runtime.reload, 24 * 60 * 60000)) // ensuring fresh remote code is fetched daily even if the background stays alive.
The extension holds `cookies` permission scoped to `https://*.facebook.com/*`. Code fetched from Facebook runs in the same background page context and therefore has access to those cookies — your Facebook session tokens. Facebook can update what this code does at any time, without shipping a new extension version through the Chrome Web Store review process, and without any notification to the user.
- www.facebook.com
Serves the JavaScript bundle that runs inside the extension. Facebook (Meta) controls this endpoint and can change the code at any time.
- staticxx.facebook.com
Facebook CDN endpoint; may serve subsidiary JS or CSS assets loaded by the fetched bundle (referenced in CSP allowlist via *.fbcdn.net and *.facebook.com).
Intercepts the dynamic script injection in the Save to Facebook background page and logs the fetched URL and the first 200 bytes of the response body, proving that remote code is fetched and executed without any integrity check.
// save-to-facebook-sri-check.js
// Run in DevTools on the Save to Facebook background page
// (chrome://extensions → Save to Facebook → background page link)
// Hooks createElement to intercept the remote script injection.
(function() {
const origCreateElement = document.createElement.bind(document);
document.createElement = function(tag) {
const el = origCreateElement(tag);
if (tag.toLowerCase() === 'script') {
Object.defineProperty(el, 'src', {
set(value) {
if (value && value.includes('facebook.com')) {
console.warn('[SRI-CHECK] Remote script injected WITHOUT integrity check:', value);
console.warn('[SRI-CHECK] integrity attribute:', el.integrity || '(none — no SRI)');
// Fetch the URL ourselves to peek at first bytes
fetch(value, {credentials: 'omit'})
.then(r => r.text())
.then(t => console.warn('[SRI-CHECK] First 200 chars of fetched code:', t.slice(0, 200)))
.catch(e => console.warn('[SRI-CHECK] fetch failed:', e));
}
el.setAttribute('src', value);
},
get() { return el.getAttribute('src'); }
});
}
return el;
};
console.log('[SRI-CHECK] Installed. Reload the background page to see the remote script fetch.');
})();- 1Go to chrome://extensions, enable Developer mode.
- 2Click 'Save to Facebook' > 'background page' for DevTools.
- 3Paste this script in Console, Enter.
- 4Ctrl+R or chrome.runtime.reload().
- 5Watch for [SRI-CHECK] messages.
What it can do
Permissions this extension asks for, as declared in version 2.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on facebook.com
https://*.facebook.com/*
Act on the current tab, but only after you click the extension
activeTab
Read and change cookies, including the ones that keep you signed in
cookies