Is YourTV Chrome extension safe?

Low risk

YourTV Chrome extension bridges web pages to a native host using eval() on both incoming and outgoing messages, creating code-execution exposure.

The extension relays messages between allowed web origins (Minerva Networks and affiliated cable-TV domains) and a local native host via chrome.runtime.onConnectExternal. Both the message received from the web page and the response received from the native host are deserialized with eval() in the extension background, rather than with a safe JSON parser. This means a cross-site scripting vulnerability on any permitted origin, or a compromise of the native host binary, could result in arbitrary JavaScript executing in the extension's privileged background context.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Minerva Networks Inc.v4.7.4Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 4.7.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Keep running in the background while your browser is open

    background

Updated 21 September 2026bdlhpbalhdjobabgbacbgclpjjelainj