Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomezShare For Zoho Social
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Production-shipped Safari extension binary has com.apple.security.get-task-allow=true in its embedded entitlements, allowing process inspection / debugger attachment and weakening exploit mitigations.
  2. 02Content scripts (jquery-1.7.1.js, init.js, z_mouse.js, content_script.js) auto-inject on every website (SFSafariWebsiteAccess: All) and scan the DOM for images on every page load to support context-menu / icon-driven sharing.
  3. 03Internal Zoho development hostnames (csez.zohocorpin.com, localzoho.com) are left as commented-out source in init.js shipped to end users.
OTHER EXTENSIONS

Is zShare For Zoho Social safe?

Medium risk

No summary available.

Zoho Corporationv2.0.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.zoho.zShare.shareextension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact