Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeUiPath Browser Automation
Findings · 3
+2 more findings locked
HIGH FINDINGS · 3
  1. 01Background and content scripts eval() arbitrary JS supplied by externally-connected pages on *.uipath.com and *.apple.com (port name com.uipath.studio_web_host); content-script eval runs in EVERY page context (manifest content_scripts.matches = http/https/file://*/*).
  2. 02externally_connectable allowlists *.apple.com — the entire Apple web property is treated as trusted by an extension whose vendor is UiPath.
  3. 03Background WebSocket relay opens arbitrary attacker-supplied WebSocket URLs on behalf of any uipath.com / apple.com page and forwards bidirectional traffic; the WS server can deliver code that LoaderPortable then eval()s.
+2 more findings locked
OTHER EXTENSIONS

Is UiPath Browser Automation safe?

Medium risk

No summary available.

UiPath Incv25.10.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.uipath.SafariNativeHost.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact