Is XDown safe?

Clean risk

XDown collects session cookies for any downloaded file's origin and forwards them to a locally installed native host on each download.

When a file download starts, XDown reads all cookies associated with the download URL using chrome.cookies.getAll and packages them into a download task sent to the native messaging host org.xdown.xmsg. The native host (a local download manager application) receives the cookies alongside the URL and referrer to facilitate authenticated downloads. Because the extension holds <all_urls> host permissions, it can collect cookies from any website the user downloads from.

libxdownv2.0.0Chrome Web Store
0Risk
Who publishes it

libxdown - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
libxdown
Website

Same store account

1 other listing published from this account, 200k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Start, monitor and manage your downloads

    downloads

  • Add items to the right-click menu

    contextMenus

Where it sends data

Destinations our analysis observed XDown contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • org.xdown.xmsg (local native host)

    XDown sends data to org.xdown.xmsg (local native host). Named as a recipient in this extension's own analysis.

Updated 30 September 2026eapmjcdkdlenhkbanlgacimfibbbiinc