Is Simple Gmail Notes safe?

Medium risk

SGNotes is medium risk. Using the CRM sharing control in Gmail makes Simple Gmail Notes build a request to sgn.mobilecrm.io with a compressed zdata value holding contacts, sender, subject, message IDs, timestamps, and notes. No completed request was recorded.

Bart Solutionsv2.9.29.55Chrome Web Store
45Risk
Who publishes it

BART SOLUTIONS LIMITED - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Bart Solutions
Declared legal entity
BART SOLUTIONS LIMITED
Registered address
EASEY COMMERCIAL BUILDING, 253-261 HENNESSY ROAD, WANCHAI 001, Hong Kong

Same store account

1 other listing published from this account, 100k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Gmail CRM shares send message metadata to MobileCRM

Using the CRM sharing control in Gmail makes Simple Gmail Notes build a request to sgn.mobilecrm.io with a compressed zdata value holding contacts, sender, subject, message IDs, timestamps, and notes.

No completed request was recorded.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click the CRM share control while viewing a Gmail message.

The content script handles the .sgn_share action from the Gmail page.

The extension did this

The extension gathers message metadata and prepares it for MobileCRM.

The share flow uses the current message ID, contacts, sender, subject, timestamps, note text, excerpts, and CRM account context.

02EvidenceFIELD TABLE
Metadata assembled for the CRM share payload
FieldValueWhy it matters
Contacts and sender
From: Pat Rivera <pat.rivera@example.com>; To: sales-team@example.com (illustrative)Lets the CRM service associate the Gmail conversation with the people shown on the message.
Subject and excerpts
Subject: Q3 renewal plan; Excerpt: Please review the attached pricing update (illustrative)Reveals the topic and a portion of the message text associated with the CRM share.
Message timestamps
2026-07-12T14:35:00-04:00, timezone offset 240 (illustrative)Shows when the Gmail message occurred and how the thread is ordered.
Message and thread IDs
messageId: 18f3a9b7c1d2e4f0; thread_id: thread-a:r427001932116 (illustrative)Lets the CRM service connect future updates to the same Gmail conversation.
Simple Gmail Notes content
note: Follow up after demo; gdrive_note_id: 1P5xR9fN2jLqY6mS3aV0 (illustrative)Includes the note text and linked Drive identifiers that the extension keeps for the message.
CRM account context
crm_user_email=alex@example.com; token value appended on logged-in CRM requests (illustrative)Ties the share request to the CRM account that is logged in for the extension.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://sgn.mobilecrm.io/crm/share_email/
The code constructs this MobileCRM share endpoint; dynamic analysis did not record a completed request because CRM account fields were empty.
04EvidenceCODE COMPARE
The code that does this

The shipped code that gathers Gmail metadata and builds the CRM share request

What it actually does
The click branch invokes the CRM share flowdeobfuscated/content.js
        if (action === "share" ) {
          debugLog("@6046ccc");
          shareToCRM(email, messageId, false, false, ev.shiftKey);
          return;
        }
The CRM email payload fieldsdeobfuscated/content.js
  //wrap up the data
  var data = {
    contacts: contacts.slice(0, 10),
    email: {
      id: messageId,
      sgn_email_date: emailDate,
      sgn_email_date_max: emailDateMax,
      sgn_email_date_timezone_offset: new Date().getTimezoneOffset(),
      email_address: email,
      note: emailNote,
      subject: subject,
      thread_id: threadId,
      latest_message_id: sgnLastMessageId,
      excerpt: excerpt,
      long_excerpt: longExcerpt,
      font_color: fontColor,
      background_color: backgroundColor,
      opportunity_id: opportunityId,
      //auto_sync: autoSync,
      note_timestamp: noteTimestamp,
      gdrive_note_id: gCurrentGDriveNoteId,
      gdrive_folder_id: gCurrentGDriveFolderId,
      from_address: fromAddress,
      is_conversation: isConversation
    },
    hide_success_page: hideSuccuess,
    sgn_sidebar_display: sgnSidebarDisplay,
  };


  //debugLog("@633", data);
  return data;
};
The metadata JSON is compressed into zdatadeobfuscated/content.js

  zData = LZString.compressToBase64(JSON.stringify(emailData));

  var data = {
    zdata: zData,
  };
The click-share path opens the MobileCRM popup URLdeobfuscated/content.js
  else{
    shareUrl = getCRMSharePopupUrl(
      getCrmUser(email), emailData, shiftKey);

    gLastCRMShareURL = shareUrl;
    data["zdata_email_id"] = messageId;

    //it has to be done by page script
    openCRMSharePopup(shareUrl, data);
  }
Builds the MobileCRM share URLdeobfuscated/content.js
var getCRMSharePopupUrl = function(userEmail, data, shiftKey){
  var url = SGNC.getCRMBaseUrl() + '/crm/share_email/?' + getCRMBaseParam() +
              '&source=sha';

  if(shiftKey)
    url += '&sk=1';
          
  url += '&token_=';

  // put the data at bottom
  url += '&zdata=' + LZString.compressToBase64(JSON.stringify(data));

  url += '&e=1'; //end character notation;
              
  return url;
};
Stores CRM account email and token for later requestsdeobfuscated/background.js
    case "update_crm_user_info":
      var crm_user_email = request.crm_user_email;
      var crm_user_token = request.crm_user_token;
      await setStorage(sender, "crm_user_email", crm_user_email);
      await setStorage(sender, "crm_user_token", crm_user_token);
      break;
Defines the MobileCRM base URLdeobfuscated/settings.js
  SHOW_SUBSCRIPTION_URGE: true,
  SHOW_SUBSCRIBER_OPTIONS: true,
  CRM_BASE_URL: "https://sgn.mobilecrm.io",
  SGN_WEB_LOGIN_BASE_URL: "https://app.simplegmailnotes.com",
05EvidenceTHIRD PARTY LIST
External service used by the CRM sharing workflow
  • sgn.mobilecrm.io

    MobileCRM backend that receives the CRM share request built by the extension.

Updated 30 September 2026jfjkcbkgjohminidbpendlodpfacgmlm