Is UiPath safe?

Low risk

UiPath downloads and executes JavaScript code supplied by a local native host in both its background page and every web page visited.

On startup, the extension contacts a native messaging host (com.uipath.chromenativemsg) to fetch JavaScript code, which it then runs via eval in its privileged background page. A parallel content script running on all http, https, and file URLs performs the same eval with code sourced from the same native host. The native host can also instruct the extension to inject and execute caller-supplied JavaScript in any open browser tab by name.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

UiPathv9.0.6423Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 9.0.6423. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See the address and title of every tab you have open

    tabs

  • See every page you navigate to, as you navigate to it

    webNavigation

Updated 21 September 2026dpncpimghfponcpjkgihfikppbbhchil