Chrome Web Store
2Versions
1Code reviewed

No malware found

In code review

Our reviewer read this extension’s code and found no malicious behaviour. Review the permissions below before installing.

12 indicators in this extension

12 indicators
1 version analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

What our analysis found

BrowseVeil - 浏览器指纹保护与防关联多开, used by 1,000 people, showed no malicious code in Extension Auditor's review. Its permissions mean it can inject scripts into pages and can observe network requests. It comes from a trusted publisher and was last updated in June 2026.

Analyst notes

The extension is a legitimate browser fingerprint obfuscation and proxy management tool consistent with its declared purpose. intercepts Canvas, WebGL, Audio, Navigator, Screen, and Date APIs to inject locally-computed noise—all data flows locally into pages from chrome.storage, not outward. The service worker sets __sps_seed cookies (1-year expiry) on visited sites to persist per-site fingerprint seeds (required for stable spoofing), uses chrome.scripting.executeScript solely to write the local profile into window.__SPS_PROFILE__, manages user-configured proxy settings via chrome.proxy.settings.set, silently supplies stored proxy credentials via onAuthRequired, and fetches the public IP from api.ip.sb and [domain withheld] declared in manifest host_permissions—for proxy-connectivity verification. The large js_hex_obfuscation (666) and js_exclamation (861) counts originate from the embedded tldts TLD-parsing library's data tables and minified Preact code, not intentional anti-analysis. The CWS-published manifest summary omits host_permissions and optional_host_permissions present in the bundled manifest (likely a CWS API display limitation), but the declared permissions are used only for IP detection and broad per-site content script injection—both core features of a fingerprint protection tool.

BrowseVeil - 浏览器指纹保护与防关联多开

BrowseVeil - 浏览器指纹保护与防关联多开 Chrome extension security report

ID: nccgpefogglgdmkhbeojgkealhibdhme

Extension Info & Metadata

Status
Active
Version
1.0.2
Size
0.51 MB
Rating
4.7/5
Reviews
3
Users
1,000
Type
Extension
Updated
Jun 21, 2026
Category
Privacy & security
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
5extensions
All still listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Trusted
Author
zaomatools.com
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Extensions
5
Active
5
Obsolete
0
Listed
5
Unlisted
0
Users
2,077

Screenshots & videos

Screenshot 2
Screenshot 3
Screenshot 4

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
proxy
Permission
Critical
This permission allows the extension to control the browser's proxy settings. Rated Critical because it can route all traffic through potentially malicious proxies, enabling man-in-the-middle attacks and traffic monitoring.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestAuthProvider
Permission
Critical
This permission allows the extension to handle authentication requests and modify authentication headers. Rated Critical because it can intercept login credentials, session tokens, and modify authentication flows to compromise accounts.
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
browsingData
Permission
High
This permission clears browsing data, history, and redis. Rated High because it can destroy evidence of malicious activity, clear security logs, and modify browser state.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
Dangerous Permission Combination: scripting,cookies,webRequest
Risk Factor
High
Enables extensions to interact with scripts, modify files and downloads, and alter browsing history and bookmarks, potentially affecting data integrity and user control.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
https://apps.game.qq.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://api.ip.sb/*
Host
Medium
Host permission — access limited to this URL pattern.

Each row lists a threat category the scanner evaluates. A checkmark means the review ran and found no matching issues in that category for this version.

  • Data Exfiltration

    Code review completed; no malicious patterns detected for this category.

  • Unauthorized Data Collection

    Code review completed; no malicious patterns detected for this category.

  • Network Interception

    Code review completed; no malicious patterns detected for this category.

  • Code Injection

    Code review completed; no malicious patterns detected for this category.

  • Credential Theft

    Code review completed; no malicious patterns detected for this category.

  • Obfuscation

    Code review completed; no malicious patterns detected for this category.

  • Tracking

    Code review completed; no malicious patterns detected for this category.

  • Privilege Escalation

    Code review completed; no malicious patterns detected for this category.

  • Phishing

    Code review completed; no malicious patterns detected for this category.

  • Remote Code Loading

    Code review completed; no malicious patterns detected for this category.

  • Other

    Code review completed; no malicious patterns detected for this category.

12 indicators in this extension

12 indicators
1 version analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

About this extension

基于本地隐私保护的浏览器指纹修改与多会话重置工具。防止跨站追踪,支持 Canvas/WebGL/Audio 指纹防关联混淆与代理配置。

Read the publisher’s full description

🌐 BrowseVeil - 浏览器指纹保护与防关联多开工具 BrowseVeil 是一款专为网络安全从业者、开发测试人员及隐私倡导者打造的专业级浏览器环境隔离与指纹混淆工具。它通过在浏览器底层对敏感指纹 API 进行动态干扰与遮罩,防止网站通过高级指纹技术跨站追踪您的真实身份,帮助您轻松实现多会话安全防关联。 🔥 核心功能特色 1. 全方位硬件与媒体指纹保护 (Fingerprint Protection) Canvas & WebGL 噪声混淆:动态注入细微像素扰动,使生成的 Canvas 图像与 WebGL 渲染指纹每次刷新都独一无二。 Audio 音频指纹防护:对 Web Audio API 的音频合成器输出进行无感混淆,阻断依赖音频硬件特征的追踪。 系统字体与媒体检测遮罩:干扰网站对本地安装字体列表的枚举,同时支持屏幕分辨率、CPU 核心数、设备内存等基础指纹的掩盖。 2. 一键多会话重置与防关联 (Session Reset) 一键清理当前站点数据:快速清除当前域名的 Cookies、LocalStorage、SessionStorage 和 IndexedDB,无需清理整个浏览器历史记录。 防关联指纹重置:一键为当前域名生成全新、随机的环境指纹凭证,配合数据清理,瞬间实现“新设备、新浏览器、新身份”的多开体验。 3. 灵活的高性能代理管理 (Proxy Manager) 多协议支持:完美支持 HTTP、HTTPS 代理。 订阅代理与自动更换 IP:支持配置代理提供商的 API 提取链接,支持一键拉取并自动更换最新 IP,方便快捷。 安全认证拦截:内置安全的代理认证凭证保存与静默填充机制,保障网络连接畅通无阻。 4. 尊享极简视觉与微交互体验 (Premium UI/UX) 科幻暗黑主题:采用 Harmonious HSL 色彩体系与毛玻璃拟物风(Glassmorphism)视觉设计,格调高端。 直观看板状态:图形化展示当前站点的保护状态、已拦截追踪项数量、当前代理 IP 及地理位置。 🎯 适用场景 网站多账号开发调试:开发人员可在同一个浏览器中快速切换不同的测试账户,无需频繁登出或使用隐私窗口。 日常隐私防护:阻断大型广告联盟及第三方追踪器的跨站行为画像收集,保护上网痕迹。 🛡️ 隐私与安全承诺 100% 本地运行:所有指纹混淆算法、代理配置、账号数据均保存在您的本地浏览器中,绝不上传至任何第三方服务器。 权限最小化:仅申请实现指纹混淆、代理和 Cookies 清理所必需的浏览器权限,代码透明合规,无任何恶意脚本。

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
9
IPv4
3

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

12 indicators in this extension

12 indicators
1 version analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe
Version
Size
Verdict
Findings
Permhash
1.0.2
Latest
0.51 MBNo malware found0
db35e219a8f802d016fade21d96879d9f09eac8d046564b1b62489e78d18c4bf
1.0.0
0.51 MBNot scanned—
db35e219a8f802d016fade21d96879d9f09eac8d046564b1b62489e78d18c4bf
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

Popular in Privacy & Security