Is UiPath Web Automation safe?

Clean risk

UiPath Web Automation loads and executes JavaScript from a local native messaging host and can inject that code into any open browser tab.

The extension connects to the native host com.uipath.chromenativemsg_v2 at startup and fetches JavaScript via a LoadScripts call; that code is executed via eval in the background page and distributed to content scripts running in all frames on every site. A separate InjectAndRunJs command allows the native host to supply arbitrary JavaScript that the extension then executes in any browser tab via chrome.tabs.executeScript. This design means the local UiPath RPA agent controls what code runs in the browser across all open pages.

UiPathv9.0.6827Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 9.0.6827. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • See, disable and uninstall your other extensions, including your security ones

    management

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See the address and title of every tab you have open

    tabs

  • See every page you navigate to, as you navigate to it

    webNavigation

Updated 21 September 2026dkgencfabioofgdmhhjljpkbbchbikbh