Chrome Web Store
10Versions
1Code reviewed

No malware found

In code review (v1.1.5)

Our reviewer read version 1.1.5 — the most recent version we have reviewed — and found no malicious behaviour. The version shown here has not been individually reviewed yet.

What our analysis found

ChatGPT, used by 6,000,000 people, showed no malicious code in Extension Auditor's review. Its permissions mean it can read and change data on all websites and can inject scripts into pages. It comes from a trusted publisher and was last updated in September 2026.

The extension is a legitimate browser automation tool from OpenAI. The content script only communicates internally via chrome.runtime and uses the permissions as required for its automation features. The CSP restricts network connections to localhost, preventing data exfiltration to remote servers. No malicious patterns found in the source code; all operations align with the stated purpose.

ChatGPT

ChatGPT Chrome extension security report

ID: hehggadaopoacecdllhhajmbjkdcmajg

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Active
Version
1.26.901.11451
Size
20.51 MB
Rating
2.8/5
Reviews
875
Users
6,000,000
Type
Extension
Updated
Sep 4, 2026
Category
Tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
3extensions
All still listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Trusted
Author
OpenAI
Country
US
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Address
3180 18th St San Francisco, CA 94110-2043 US
Website
Visit
Extensions
3
Active
3
Obsolete
0
Listed
3
Unlisted
0
Users
11,000,000

Screenshots & videos

Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4
Screenshot 5
Screenshot 6
Screenshot 7
Screenshot 8

Install growth

Item
Type
Severity
Description
debugger
Permission
Critical
This permission grants the extension ability to debug and control other extensions and browser tabs. Rated Critical because it can access and modify other extensions' internal state, inject code, and access sensitive data from any tab.
declarativeNetRequestWithHostAccess
Permission
Critical
This permission combines network request modification with host permissions. Rated Critical because it can modify requests for specific domains, potentially targeting sensitive websites with precise attack rules.
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
downloads
Permission
High
This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns.
history
Permission
High
This permission grants access to your complete browsing history. Rated High because it can track all visited websites, reveal sensitive browsing patterns, and expose private information.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
sessions
Permission
High
This permission accesses recently closed tabs and windows. Rated High because it can monitor user activity, recover closed sensitive pages, and track browsing patterns.
topSites
Permission
High
This permission accesses the list of most visited websites. Rated High because it can reveal browsing patterns, identify frequently accessed service, and gather user behavior data.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
Dangerous Permission Combination: history,tabs,webNavigation,topSites
Risk Factor
High
Enables extensive monitoring and access to sensitive aspects of your digital activities.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabGroups
Permission
Medium
This permission manages tab grouping functionality. Rated Medium because it can monitor tab organization, track user workflow patterns, and modify tab relationships.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.
bookmarks
Permission
Low
This permission manages browser bookmarks and folders. Rated Low because it can only modify bookmark data, which is not sensitive and changes are visible to users.
favicon
Permission
Low
This permission accesses website favicon images. Rated Low because it only retrieves publicly visible website icons.
notifications
Permission
Low
This permission displays system notifications. Rated Low because it can only show user-visible notifications without accessing system data.
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
sidePanel
Permission
Low
This permission adds custom panels to the browser interface. Rated Low because it only affects browser UI elements and cannot access page content.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Control Chrome with Codex.

Read the publisher’s full description

Codex can now use Chrome on your computer to complete work inside the websites and apps where you’re already signed in. OVERVIEW Codex for Chrome lets Codex help with work that happens inside the websites and apps where you are already signed in. Use it when a task depends on browser context, account state, or websites. Codex can help you with research, update records, review dashboards, fill forms, and move through multi-step workflows across logged-in tools like CRMs & internal apps, as well as external websites. Codex works in task-specific tab groups, so it can gather context and take actions without taking over your active browsing session. It will help ask you to take over when needed, and keeps useful pages for review when it's finished. You stay in control. Codex always asks before sensitive actions. It will ask before accessing sites in Chrome, referencing your browser history, and downloading/uploading files. WHAT YOU CAN DO Research and context on specific websites Fill forms or prepare requests, then stop for your confirmation Review dashboards or internal tools and summarize findings Test and validate websites across multiple tabs Organize and clean up your tabs GETTING STARTED Install the Codex Chrome extension. Install the Chrome plugin inside Codex Ask Codex for help with a browser-based task. Review and approve site access when prompted. Note: Codex does not support other Chromium-based web browsers at the moment.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
321
IPv4
73

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
1.26.901.11451
Latest
20.51 MBNot scanned—
2a3f9a792a41c7add47df2161bed041b42afad257061a92d2298a3fe19fa7c96
1.26.827.12125
21.26 MBNot scanned—
47308500f2cca34b8c3cb326ff7b2d35c807910c51b7d3c32390768a0ecef9c0
1.2.27268.51612
14.51 MBNot scanned—
47308500f2cca34b8c3cb326ff7b2d35c807910c51b7d3c32390768a0ecef9c0
1.2.27267.15375
14.58 MBNot scanned—
47308500f2cca34b8c3cb326ff7b2d35c807910c51b7d3c32390768a0ecef9c0
1.2.27259.19709
14.58 MBNot scanned—
d2cf46b9616322fcdfac0a79b7c9fa386a8a067e000a78de939253797e7751f2
1.2.27236.6274
14.33 MBNot scanned—
47308500f2cca34b8c3cb326ff7b2d35c807910c51b7d3c32390768a0ecef9c0
1.2.27221.15725
9.04 MBNot scanned—
dad977c5097694b8569704a32154697500253e01040f599783402ae8e3411bad
1.2.27203.26575
21.16 MBNot scanned—
dad977c5097694b8569704a32154697500253e01040f599783402ae8e3411bad
1.1.5
0.13 MBNo malware found0
d2cf46b9616322fcdfac0a79b7c9fa386a8a067e000a78de939253797e7751f2
1.1.4
0.11 MBNot scanned—
d2cf46b9616322fcdfac0a79b7c9fa386a8a067e000a78de939253797e7751f2
Showing 1 to 10 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

More from OpenAI