Is Yandex Access safe?

Low risk

Yandex Access injects users' real IP addresses into proxied requests and sends daily telemetry with a persistent UUID to Yandex servers.

When acting as a proxy, the extension fetches the user's public IP and adds it as an X-Forwarded-For header on every proxied request, exposing the real IP to destination servers. Every 20 minutes it fetches a remote server config and probes a list of server-directed URLs, reporting reachability results (timing, status codes) to Yandex statistics. Daily, it transmits a persistent device UUID, browser version, and OS type to soft.export.yandex.ru, and writes extension metadata into the ys cookie on Yandex-family domains.

Yandexv5.2.0Chrome Web Store
20Risk
Who publishes it

Joint-stock company (Aktiengesellschaft) - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Yandex
Declared legal entity
Joint-stock company (Aktiengesellschaft)
Registered address
Werftestrasse 4, Luzern 6005, CH
Registered contact
Intertech Services AG

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityLOW
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Extension Probes Arbitrary URLs on Command, Reports Results to Yandex

Every 20 minutes, Yandex Access downloads a config from a Yandex CDN.

If it lists 'direct_check_urls', the extension GETs each, measuring reachability, then reports to a telemetry endpoint.

Probed URLs are set entirely by remote config.

01EvidenceCAUSE EFFECT
What actually happens
You did this

Yandex Access is installed and running.

The extension registers a Chrome alarm named 'check-experiment' on install, set to fire every 20 minutes.

The extension did this

The extension fetches a remote configuration and, if it contains probe targets, sends GET requests to each listed URL from your browser and reports the results to Yandex.

The probe list is read from the 'direct_check_urls' field of the remote configuration served at d1cv6bu0xiop18.cloudfront.net. It can be updated at any time without shipping an extension update.

02EvidenceTEMPORAL PATTERN
When this fires
Every 20 minutes

On install and every 20 minutes thereafter, the extension's mainLoopIteration() function runs the probe cycle. The alarm also fires on browser startup via chrome.runtime.onStartup after a 3-second hold.

03EvidenceNETWORK CAPTURE
Captured request
GEThttps://cellar.z5h64q92x9.net/nearest
Observed during dynamic analysis: fetch error (connection refused), response time 36.8 ms. The extension records the outcome as state='fetch-error' and includes this in the subsequent telemetry report to Yandex.
04EvidenceNETWORK CAPTURE
Captured request
GEThttps://yandex.ru/clck/click/dtype=stred/pid=457/cid=73589/path=direct-check-results/vars=-results=%5B%7B%22url%22%3A%22cellar.z5h64q92x9.net%2Fnearest%22%2C%22state%22%3A%22fetch-error%22%2C%22time%22%3A36.8%7D%2C%7B%22url%22%3A%22loft.z5h64q92x9.net%2Fnearest%22%2C%22state%22%3A%22fetch-error%22%2C%22time%22%3A48.5%7D%5D/cts=1751071784000/*
HTTP 200 OK. Confirmed by dynamic analysis. The vars parameter carries the JSON-serialized probe results array. URL shown above is illustrative, timestamp is representative; actual values matched the real probe timing.
05EvidenceFIELD TABLE
Fields recorded for each probed URL and sent to Yandex telemetry
FieldValueWhy it matters
Probed URL
cellar.z5h64q92x9.net/nearestThe full URL of the host the extension tested for reachability on your behalf, as delivered by the remote configuration.
Response time
36.8How long your browser took to reach, or fail to reach, the target host, measured in milliseconds.
Outcome state
fetch-errorWhether the probe succeeded, timed out, or returned an error. This reveals the reachability of the target host from your network.
HTTP status code
200The HTTP response code returned by the target host when a response is received.
06EvidenceCODE COMPARE
The code that does this

Probe-and-report chain, shipped source vs annotated readable form

What it actually does
DirectCheckController: read remote-config URL list, probe each, send resultsevent_page.js
// DIRECT_CHECK_TIMEOUT = 20000 ms (20 seconds)
// config.directCheckUrls is populated from 'direct_check_urls' in the remote JSON config.
// If the field is absent or empty, the probe cycle is skipped entirely.
class DirectCheckController {
  static async runChecks(config) {
    const urls = config.directCheckUrls;
    if (!urls || !urls.length) {
      return []; // No probing if the remote config omits the field.
    }
    // Probe all listed URLs in parallel.
    const results = await Promise.all(urls.map(DirectCheckController.runCheck));
    // Ship all results to Yandex telemetry in a single call.
    await Statistic.directCheckResults(results);
    return results;
  }

  static async runCheck(url) {
    const start = window.performance.now();
    try {
      const result = await sendWebRequest({ url, method: 'GET', timeout: 20000 });
      return {
        url,
        state: 'fetch-success',
        time: performance.now() - start,   // milliseconds
        code: result.code,                 // HTTP status code
        contentLength: typeof result.data === 'string' ? result.data.length : -1
      };
    } catch (error) {
      if (error instanceof WebRequestTimeout) {
        return { url, state: 'fetch-timeout', time: performance.now() - start };
      } else if (error instanceof WebRequestHttpError) {
        return {
          url, state: 'fetch-http-error',
          time: performance.now() - start,
          code: error.code,
          contentLength: typeof error.response === 'string' ? error.response.length : -1
        };
      }
      // Network error (e.g. host unreachable)
      return { url, state: 'fetch-error', time: performance.now() - start };
    }
  }
}
Statistic: serialise results and dispatch to Yandex telemetry endpointevent_page.js
class Statistic {
  // Constructs and fires a no-cors GET to the Yandex /clck/click telemetry endpoint.
  // credentials:include means browser cookies for yandex.ru are attached if present.
  static async send(message) {
    const vars = message.additionalVars || [];
    const url =
      'https://yandex.ru/clck/click/dtype=stred/pid=457/cid=73589' +
      `/path=${message.event}` +
      `/vars=${vars.map(([k, v]) => `-${encodeURIComponent(k)}=${encodeURIComponent(v)}`).join(',')}` +
      `/cts=${message.timestamp}` +
      '/*';
    await window.fetch(url, { mode: 'no-cors', credentials: 'include' });
  }

  // Called by DirectCheckController.runChecks() after all probes complete.
  // Serialises the full probe result array as JSON and enqueues it for dispatch.
  static async directCheckResults(results) {
    await this.pushMessageAndSendQueue(
      'direct-check-results',       // becomes /path=direct-check-results in the URL
      [['results', JSON.stringify(results)]]  // becomes /vars=-results=<url-encoded JSON>
    );
  }
}
07EvidenceTHIRD PARTY LIST
External hosts involved in the probe-and-report chain
  • d1cv6bu0xiop18.cloudfront.net

    Yandex CloudFront CDN delivering the remote config (config_5_0_P.json). Its direct_check_urls field sets which URLs the extension probes, updatable anytime.

  • yandex.ru

    Receives probe results via /clck/click (path=direct-check-results): probed URL, outcome, response time. Operated by Yandex LLC.

What it can do

Permissions this extension asks for, as declared in version 5.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Schedule its own background tasks

    alarms

  • Route all of your browsing through a server of its choosing

    proxy

  • Store data in your browser

    storage

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Run its own code inside the pages you visit

    scripting

Where it sends data

Destinations our analysis observed Yandex Access contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • yandex.ru

    Yandex Access sends data to yandex.ru. 10 other extensions we have analysed send data here.

  • soft.export.yandex.ru

    Yandex Access sends data to soft.export.yandex.ru. 3 other extensions we have analysed send data here.

  • d1cv6bu0xiop18.cloudfront.net

    Yandex Access sends data to d1cv6bu0xiop18.cloudfront.net. No other extension we have analysed sends data here.

Updated 30 September 2026oakfpjifgmfpainopanfgfckhkcfgacb