Is Youtube Unblocked safe?

Medium risk

Youtube Unblocked is medium risk. When enabled, the extension can change proxy settings for YouTube-related sites and record a counter each time setup succeeds. Dynamic analysis observed the server set to `server1`, state marked connected, counter changing from 2 to 3.

epubreadsoftv5.9Chrome Web Store
45Risk
Who publishes it

epubreadsoft - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
epubreadsoft

Same store account

1 other listing published from this account, 1k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Proxy setup records a local connection counter

When enabled, the extension can change proxy settings for YouTube-related sites and record a counter each time setup succeeds.

Dynamic analysis observed the server set to `server1`, state marked connected, counter changing from 2 to 3.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The extension starts and reads the saved proxy state for this browser.

If the saved target state is connected, it proceeds to enable a proxy path.

The extension did this

The extension installs a PAC script and records another proxy connection in local storage.

Dynamic analysis observed `selectedServer=server1`, `currentState=connected`, and `connectionCount` changing from 2 to 3.

02EvidenceFIELD TABLE
Fields and values used by the proxy setup path
FieldValueWhy it matters
Selected proxy server
server1Shows which proxy path the extension will install for your browser.
Proxy state
connectedShows whether the extension considers the proxy path active on your browser.
Proxy connection counter
connectionCount: 3Shows that the extension records successful proxy setup activity on your device.
Device identifier
8f3a42c-9b12-4d63-a8e7-5c901b24d6af (illustrative)Lets the proxy assignment service link a proxy request to the same browser over time.
Public IP address
198.51.100.24 (illustrative)Tells the proxy assignment service which internet connection your browser is using.
03EvidenceSTORAGE DUMP
What's stored on your device

This local record shows the extension treating the proxy as connected and counting another successful proxy setup on your browser.

Locationchrome.storage.local proxy state keys
Contents (JSON)
{
  "currentState": "connected",
  "selectedServer": "server1",
  "connectionCount_after": 3,
  "connectionCount_before": 2
}
04EvidenceNETWORK CAPTURE
Captured request
POSThttps://uubb.website/api/v1/get-proxy
The code expects a JSON response containing proxy `host` and `port`, then installs those values into the PAC script.
Headers
Content-Typeapplication/json
05EvidenceCODE COMPARE
The code that does this

The shipped code installs proxy settings and increments the counter

What it actually does
Counter update in the deobfuscated background scriptbackground.js
function incrementProxyConnectionCount() {
  chrome.storage.local.get("connectionCount", o => {
    let n = o.connectionCount || 0;
    chrome.storage.local.set({
      connectionCount: n + 1
    }), console.log("incrementProxyConnectionCount: New connection count = ", n + 1)
  })
}
Remote proxy assignment path in the deobfuscated background scriptbackground.js
const loadThirdServer = () => {
  function o() {
    const o = "xxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx".replace(/[xy]/g, function(o) {
      const n = 16 * Math.random() | 0;
      return ("x" === o ? n : 3 & n | 8).toString(16)
    });
    return chrome.storage.local.set({
      deviceId: o
    }, function() {}), o
  }
  chrome.storage.local.set({
    currentState: "connecting"
  }), fetch("https://raw.githubusercontent.com/vpn-naruzhu/public/main/uboost-extension").then(o => o.json()).then(n => {
    const e = n.apiBaseUrl;
    var t;
    console.log(e, "apiBaseUrl result"), t = function(o) {
      var n;
      o || console.warn("enableProxy: Failed to retrieve device ID, proceeding without it."), n = function(n) {
        n || console.warn("enableProxy: Failed to retrieve public IP address, proceeding without it."), fetch(`https://${e}/api/v1/get-proxy`, {
          method: "POST",
          headers: {
            "Content-Type": "application/json"
          },
          body: JSON.stringify({
            device_id: o || "unknown",
            device_ip: n || "unknown"
          })
        }).then(o => o.json()).then(o => {
          const n = o.host,
            e = o.port;
          chrome.proxy.settings.set({
            value: {
              mode: "pac_script",
              pacScript: {
                data: `
                                    function FindProxyForURL(url, host) {
                                        if (dnsDomainIs(host, ".googlevideo.com") ||
                                            dnsDomainIs(host, ".youtube.com") ||
                                            dnsDomainIs(host, ".ytimg.com") ||
                                            dnsDomainIs(host, ".ggpht.com")) {
                                            return "PROXY ${n}:${e}";
                                        }
                                        return "DIRECT";
                                    }
                                    `
              }
            },
            scope: "regular"
          }, () => {
            chrome.runtime.lastError ? chrome.storage.local.set({
              currentState: "error"
            }) : (chrome.storage.local.set({
              currentState: "connected"
            }), reloadCurrentActiveYouTubeTab(), incrementProxyConnectionCount())
          })
        }).catch(o => {
          chrome.storage.local.set({
            currentState: "error"
          })
        })
      }, fetch("https://api.ipify.org?format=json").then(o => o.json()).then(o => {
        n(o.ip)
      }).catch(o => {
        n(null)
      })
    }, chrome.storage.local.get(["deviceId"], function(n) {
      if (n.deviceId) t(n.deviceId);
      else {
        const n = o();
        t(n)
      }
    })
  }).catch(o => {
    chrome.storage.local.set({
      currentState: "error"
    })
  })
};
Embedded PAC path in the deobfuscated background scriptbackground.js
const loadDirectServer = (o, n, e) => {
  (o || "server1") !== this.value && (chrome.proxy.settings.set({
    value: {
      mode: "pac_script",
      pacScript: {
        data: serverConfigs[o]
      }
    },
    scope: "regular"
  }, () => {
    chrome.runtime.lastError ? (chrome.storage.local.set({
      currentState: "error"
    }), console.error("enableProxy: Error setting proxy:", chrome.runtime.lastError.message)) : (chrome.storage.local.set({
      currentState: "connected"
    }), incrementProxyConnectionCount(), console.log("enableProxy: Proxy has been set successfully."))
  }), reloadCurrentActiveYouTubeTab(), incrementProxyConnectionCount())
};
06EvidenceTHIRD PARTY LIST
Remote hosts and proxy endpoints referenced by the shipped code
  • raw.githubusercontent.com

    Hosts the extension's remote configuration file that currently names `uubb.website` as the proxy assignment API base.

  • uubb.website

    Receives the proxy assignment request and is expected by the code to return a proxy host and port.

  • api.ipify.org

    Receives a request for the browser's public IP address before the proxy assignment request.

  • 193.233.165.68:63228

    Embedded PAC endpoint used by server1 for YouTube-related domains.

  • 72.56.217.130:63126

    Embedded PAC endpoint used by server2 for YouTube-related domains.

  • 185.69.221.185:48932

    Embedded PAC endpoint used by server8 for all hosts except the code's excluded domains.

Updated 30 September 2026apmbfchnaiociljffgngpjkhplkengck