Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeNotebook - Notes, To do
Findings · 3
+4 more findings locked
HIGH FINDINGS · 3
  1. 01IPC_ACTION.SAFARI_API_REQUEST (action=2006) lets any web page make page-controlled HTTP requests — including method, URL, headers, body, and multipart form data — through the host app's network code, with the response body returned to the page.
  2. 02IPC_ACTION.SAFARI_GET_DATA (action=2003) lets any web page read arbitrary keys from the extension's local storage, including the `znbcsr` Zoho session cookie and the `userprofile` JSON (zuid, email, name, account TLD).
  3. 03Content script registers an unauthenticated window.postMessage IPC handler on every page (SFSafariWebsiteAccess: All) that exposes ~25 IPC_ACTION operations (storage read/write, HTTP via host app, account window opening, feedback submission) with no event.origin / event.source check.
+4 more findings locked
OTHER EXTENSIONS

Is Notebook - Notes, To do safe?

High risk

No summary available.

Zoho Corporationv5.9.13Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+4 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.zoho.notebook.mac.safariextension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact