Is Sound Booster Max safe?
Sound Booster Max is high risk. Sound Booster Max creates or reuses a UUID in local storage when installed or updated. DA found the same UUID in chrome.storage.local and in all five observed POSTs to volumeboostermax.com/api/reports, linking reports to one profile.…
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Persistent ID Links Browsing Reports
Sound Booster Max creates or reuses a UUID in local storage when installed or updated.
DA found the same UUID in chrome.storage.local and in all five observed POSTs to volumeboostermax.com/api/reports, linking reports to one profile.
You install or update the extension.
The extension creates or reuses a stored ID that is sent with later browsing reports.
This stored ID lets separate browsing reports be associated with the same browser profile.
chrome.storage.local key 'uid'{
"uid": "64d63d18-7dfa-4edb-8c0e-ccfaa4f093bc"
}| Field | Value | Why it matters | |
|---|---|---|---|
Stored user ID | 64d63d18-7dfa-4edb-8c0e-ccfaa4f093bc | Lets repeated reports be tied back to the same browser profile. | |
Current page address | https://en.wikipedia.org/wiki/[planted marker redacted] | Shows which page was associated with that stored ID. | |
Previous page address | https://www.google.com/account/about/?hl=en-US | Adds context about the page that preceded the current visit. |
| Content-Type | application/json |
The service worker creates and reuses the stored ID
generateUserId = () => "undefined" != typeof crypto && crypto.randomUUID ? crypto.randomUUID() : "xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx".replace(/[xy]/g, (function(e) {
const t = 16 * Math.random() | 0;
return ("x" === e ? t : 3 & t | 8).toString(16)
})), initializeUserId = async () => {
try {
const e = await getFromChromeLocalStorage("uid");
if (!e) {
const e = generateUserId();
return await setToChromeLocalStorage("uid", e), e
}
return e
} catch (e) {
return console.error("Error initializing user ID:", e), null
}
}chrome.runtime.onInstalled.addListener((async e => {
"install" === e.reason ? (await initializeUserId(), chrome.tabs.create({
url: "http://volumeboostermax.com/#how-to-use"
}), chrome.runtime.setUninstallURL("https://forms.gle/V3ugXXMc8V9YF1hn6")) : "update" === e.reason && (await initializeUserId(), chrome.runtime.setUninstallURL("https://forms.gle/V3ugXXMc8V9YF1hn6"))
}))- volumeboostermax.com
Receives /api/reports requests that include the stored UUID with browsing URL and referrer fields.
Browsing URLs Posted on Every Page Load
We observed Sound Booster Max POST to volumeboostermax.com/api/reports on every tested navigation: the current URL, the prior URL when available, and a persistent user ID.
One request carried a planted marker, confirming exfiltration.
You open or finish loading a web page.
The extension sends that page address, the previous address, and a stored ID to volumeboostermax.com.
| Field | Value | Why it matters | |
|---|---|---|---|
Current page address | https://en.wikipedia.org/wiki/[planted marker redacted] | Shows the exact page you just loaded. | |
Previous page address | https://www.google.com/account/about/?hl=en-US | Shows the page that was recorded before this tab changed to the new page. | |
Stored user ID | 64d63d18-7dfa-4edb-8c0e-ccfaa4f093bc | Lets repeated browsing reports be tied to the same browser profile over time. |
| Content-Type | application/json |
{
"uri": "https://en.wikipedia.org/wiki/[planted marker redacted]",
"userId": "64d63d18-7dfa-4edb-8c0e-ccfaa4f093bc",
"ref": "https://www.google.com/account/about/?hl=en-US"
}The service worker posts navigation reports
postData = async (e, t = {}) => {
try {
const r = await fetch(e, {
method: "POST",
credentials: "include",
headers: {
"Content-Type": "application/json"
},
body: JSON.stringify(t)
});
return await r.json()
} catch (e) {}
}chrome.tabs.onUpdated.addListener((async (e, t, r) => {
if ("complete" === t.status) {
handleRuntimeError();
const t = await getFromChromeLocalStorage("uid"),
o = await tabInfo(e);
let s = o?.url;
if (isValidPage(r.url) && r.url !== s) {
let o = {
uri: r.url,
userId: t,
ref: s
};
await postData("https://volumeboostermax.com/api/reports", o);
let n = await getFromSessionStorage("referrers") || {};
n[e] = {
url: r.url
}, await setToSessionStorage("referrers", n)
}
}
}))- volumeboostermax.com
Receives POST requests to /api/reports containing page URL, referrer, and stored user ID.
Active tab URL sent from the report button
When you click Sound Booster Max's popup report button, it reads your active tab's URL and POSTs to volumeboostermax.com/api/report.
Fields are the stored user ID and tab URL; earlier testing recorded no completed request.
You click the popup's Report link after a site is not working as expected.
The visible popup text says "Not working here?" next to the Report button.
The extension reads your active tab URL and adds it to the report request.
The request also includes the extension's stored user ID.
| Field | Value | Why it matters | |
|---|---|---|---|
Current page URL | https://mail.google.com/mail/u/0/#inbox (illustrative) | Shows the page open when you clicked Report. On account or workplace pages, the URL can reveal what service and record you were viewing. | |
Extension user ID | 8d2b1a1e-8e41-4d9d-9a0b-5c8f8f5f2d41 (illustrative) | Lets reports from the same browser profile be tied together over time. | |
Active-tab context | active tab in current window (illustrative) | Shows that the URL comes from the tab you were actively using in the current window. |
| Accept | application/json |
| Content-Type | application/json |
Report submission code in the shipped popup bundle
reportIssue: async () => {
try {
const o = await fi("uid") || "unknown";
let r = "";
if (typeof chrome < "u" && chrome.tabs) {
const h = await new Promise(v => {
chrome.tabs.query({
active: !0,
currentWindow: !0
}, v)
});
h.length > 0 && (r = h[0].url || "")
}
const f = await fetch("https://volumeboostermax.com/api/report", {
method: "POST",
headers: {
Accept: "application/json",
"Content-Type": "application/json"
},
body: JSON.stringify({
userId: o,
url: r
})
});
if (!f.ok) throw new Error(`HTTP error! status: ${f.status}`);
return {
success: !0
}
} catch (o) {
return console.error("Error reporting issue:", o), {
success: !1,
error: o.message
}
}
}function x1() {
const {
reportIssue: i
} = Kn(), [d, o] = B.useState(!1), [r, f] = B.useState(!1), h = () => {
const E = "https://chromewebstore.google.com/detail/sound-booster-max/gjcagjbeioeicpajpeigkppoicofljfj/reviews";
typeof chrome < "u" && chrome.tabs ? chrome.tabs.create({
url: E
}) : window.open(E, "_blank")
}, v = async () => {
if (!(d || r)) {
o(!0);
try {
(await i()).success && (f(!0), setTimeout(() => {
f(!1)
}, 3e3))
} catch (E) {
console.error("Error in report handler:", E)
} finally {
o(!1)
}
}
};
return C.jsxs("div", {
className: "w-full bg-gray-50 dark:bg-gray-800 border-t border-gray-200 dark:border-gray-700 min-h-[40px] flex items-center justify-between px-2 sm:px-3 py-1.5 flex-wrap gap-x-2 gap-y-1",
children: [C.jsxs("div", {
className: "flex items-center gap-1 min-w-0",
children: [C.jsx("span", {
className: "text-yellow-500 text-xs flex-shrink-0",
children: "⭐"
}), C.jsx("button", {
onClick: h,
className: "text-xs text-blue-600 dark:text-blue-400 hover:text-blue-700 dark:hover:text-blue-300 font-medium underline cursor-pointer transition-colors break-words min-w-0",
children: Be("rateUs")
})]
}), C.jsxs("div", {
className: "flex items-center gap-1 min-w-0",
children: [C.jsx("span", {
className: "text-xs text-gray-600 dark:text-gray-400 break-words",
children: Be("notWorkingHere")
}), r ? C.jsx("span", {
className: "text-xs text-green-600 dark:text-green-400 font-medium break-words",
children: Be("reported")
}) : d ? C.jsx("span", {
className: "text-xs text-gray-600 dark:text-gray-400 font-medium break-words",
children: Be("reporting")
}) : C.jsx("button", {
onClick: v,
className: "text-xs text-blue-600 dark:text-blue-400 hover:text-blue-700 dark:hover:text-blue-300 font-medium underline cursor-pointer transition-colors break-words",
children: Be("report")
})]
})]
})
}- volumeboostermax.com
Receives the popup issue-report POST at /api/report, including the active tab URL and extension user ID assembled by popup.js.