Is Yandex Access safe?
Yandex Access injects users' real IP addresses into proxied requests and sends daily telemetry with a persistent UUID to Yandex servers.
When acting as a proxy, the extension fetches the user's public IP and adds it as an X-Forwarded-For header on every proxied request, exposing the real IP to destination servers. Every 20 minutes it fetches a remote server config and probes a list of server-directed URLs, reporting reachability results (timing, status codes) to Yandex statistics. Daily, it transmits a persistent device UUID, browser version, and OS type to soft.export.yandex.ru, and writes extension metadata into the ys cookie on Yandex-family domains.
Who publishes itJoint-stock company (Aktiengesellschaft) - no other listings under this identity
Joint-stock company (Aktiengesellschaft) - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Extension Probes Arbitrary URLs on Command, Reports Results to Yandex
Every 20 minutes, Yandex Access downloads a config from a Yandex CDN.
If it lists 'direct_check_urls', the extension GETs each, measuring reachability, then reports to a telemetry endpoint.
Probed URLs are set entirely by remote config.
Yandex Access is installed and running.
The extension registers a Chrome alarm named 'check-experiment' on install, set to fire every 20 minutes.
The extension fetches a remote configuration and, if it contains probe targets, sends GET requests to each listed URL from your browser and reports the results to Yandex.
The probe list is read from the 'direct_check_urls' field of the remote configuration served at d1cv6bu0xiop18.cloudfront.net. It can be updated at any time without shipping an extension update.
On install and every 20 minutes thereafter, the extension's mainLoopIteration() function runs the probe cycle. The alarm also fires on browser startup via chrome.runtime.onStartup after a 3-second hold.
| Field | Value | Why it matters | |
|---|---|---|---|
Probed URL | cellar.z5h64q92x9.net/nearest | The full URL of the host the extension tested for reachability on your behalf, as delivered by the remote configuration. | |
Response time | 36.8 | How long your browser took to reach, or fail to reach, the target host, measured in milliseconds. | |
Outcome state | fetch-error | Whether the probe succeeded, timed out, or returned an error. This reveals the reachability of the target host from your network. | |
HTTP status code | 200 | The HTTP response code returned by the target host when a response is received. |
Probe-and-report chain, shipped source vs annotated readable form
// DIRECT_CHECK_TIMEOUT = 20000 ms (20 seconds)
// config.directCheckUrls is populated from 'direct_check_urls' in the remote JSON config.
// If the field is absent or empty, the probe cycle is skipped entirely.
class DirectCheckController {
static async runChecks(config) {
const urls = config.directCheckUrls;
if (!urls || !urls.length) {
return []; // No probing if the remote config omits the field.
}
// Probe all listed URLs in parallel.
const results = await Promise.all(urls.map(DirectCheckController.runCheck));
// Ship all results to Yandex telemetry in a single call.
await Statistic.directCheckResults(results);
return results;
}
static async runCheck(url) {
const start = window.performance.now();
try {
const result = await sendWebRequest({ url, method: 'GET', timeout: 20000 });
return {
url,
state: 'fetch-success',
time: performance.now() - start, // milliseconds
code: result.code, // HTTP status code
contentLength: typeof result.data === 'string' ? result.data.length : -1
};
} catch (error) {
if (error instanceof WebRequestTimeout) {
return { url, state: 'fetch-timeout', time: performance.now() - start };
} else if (error instanceof WebRequestHttpError) {
return {
url, state: 'fetch-http-error',
time: performance.now() - start,
code: error.code,
contentLength: typeof error.response === 'string' ? error.response.length : -1
};
}
// Network error (e.g. host unreachable)
return { url, state: 'fetch-error', time: performance.now() - start };
}
}
}class Statistic {
// Constructs and fires a no-cors GET to the Yandex /clck/click telemetry endpoint.
// credentials:include means browser cookies for yandex.ru are attached if present.
static async send(message) {
const vars = message.additionalVars || [];
const url =
'https://yandex.ru/clck/click/dtype=stred/pid=457/cid=73589' +
`/path=${message.event}` +
`/vars=${vars.map(([k, v]) => `-${encodeURIComponent(k)}=${encodeURIComponent(v)}`).join(',')}` +
`/cts=${message.timestamp}` +
'/*';
await window.fetch(url, { mode: 'no-cors', credentials: 'include' });
}
// Called by DirectCheckController.runChecks() after all probes complete.
// Serialises the full probe result array as JSON and enqueues it for dispatch.
static async directCheckResults(results) {
await this.pushMessageAndSendQueue(
'direct-check-results', // becomes /path=direct-check-results in the URL
[['results', JSON.stringify(results)]] // becomes /vars=-results=<url-encoded JSON>
);
}
}- d1cv6bu0xiop18.cloudfront.net
Yandex CloudFront CDN delivering the remote config (config_5_0_P.json). Its direct_check_urls field sets which URLs the extension probes, updatable anytime.
- yandex.ru
Receives probe results via /clck/click (path=direct-check-results): probed URL, outcome, response time. Operated by Yandex LLC.
What it can do
Permissions this extension asks for, as declared in version 5.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
Read and change cookies, including the ones that keep you signed in
cookies
Schedule its own background tasks
alarms
Route all of your browsing through a server of its choosing
proxy
Store data in your browser
storage
Block and redirect the requests your browser makes
declarativeNetRequest
Run its own code inside the pages you visit
scripting
Where it sends data
Destinations our analysis observed Yandex Access contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- yandex.ru
Yandex Access sends data to yandex.ru. 10 other extensions we have analysed send data here.
- soft.export.yandex.ru
Yandex Access sends data to soft.export.yandex.ru. 3 other extensions we have analysed send data here.
- d1cv6bu0xiop18.cloudfront.net
Yandex Access sends data to d1cv6bu0xiop18.cloudfront.net. No other extension we have analysed sends data here.