Google Meet Auto Admit

Google Meet Auto Admit

ID: pabkjoplheapcclldpknfpcepheldbga

Could be malicious

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Removed
Version
12.0
Size
0.60 MB
Rating
3.0/5
Reviews
29
Users
30,000
Type
Extension
Updated
Sep 25, 2024
Category
Productivity Workflow
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
https://meetingtv.usView Profile
Country
US
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Address
6450 Lusk Blvd San Diego, CA 92121 US
Website
Visit
Total Extensions
5
Active
0
Obsolete
5
Listed
5
Unlisted
0
Total Users
347,000
Screenshot 1

Google Meet Auto Admit by smashciotechky

Sponsored by MeetingTV.us - the world's first FREE webinar service. No charge, ever, even for unlimited number of attendees. Stop paying thousands and do a webinar for free at MeetingTV.us. ==================================================== Automatically admit join requests from external guests to Google Meet Automatically click the "Admit" button when a join request comes in from external guests. If you install this extension in chrome then in Google meet rooms it will automatically lets users login by clicking the admit button on the popup. You can switch the extension from its menu. As default it checks for popup with submit button "Admit". No personally identifying information is ever captured or stored with this extension. Software is provided by Zoomcorder.com - the video bot service to record ANY video meeting WITHOUT attending and without being the host. 50% of people miss webinars they sign up to attend. With Zoomcorder - you can schedule it to record ANY video meeting and have a recording sent to you immediately after the meeting is over. Zoomcorder.com works flawlessly with Zoom, GoToMeeting, GoToWebinar, Microsoft Team, or Google Meet meetings. Give it a try and never miss another important video meeting.

Item
Type
Severity
Description
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.

By severity

Critical2
High3
Medium1
Low0

Versions scanned

Showing 1 of 7 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
11.06

Files with findings

2 distinct paths — top paths by unique finding count:

  • background.js3
  • content.js3
S.No.
Category
Severity
File
Summary
Found in Version
1Data Exfiltration
critical
background.js (line 24)The background listener writes scraped webinar 'show' and 'speaker' objects from the content script to the remote Firebase Realtime Database under webinars/shows and webinars/speakers. This is the receive-and-upload h…
2Unauthorized Data Collection
critical
content.js (line 237)On any Zoom registration page the content script silently scrapes the meeting topic, description, full time/timezone string, registration URL, custom images, and every speaker's name, title, bio and headshot URL, then…
3Data Exfiltration
high
background.js (line 1)The background service worker initializes a third-party Firebase Realtime Database (zoocorder.firebaseio.com) owned by the extension author. This is a covert exfiltration channel: data scraped from pages by the conten…
4Phishing
high
content.js (line 514)The content script injects an authoritative-looking message ('Sorry, but this webinar is over...') and an outbound link to zoomcorder.com directly inside Zoom's own webinar_register_container, impersonating Zoom UI. M…
5Unauthorized Data Collection
high
content.js (line 128)Across goto.com/gotowebinar.com/zoom.us pages the script injects custom DOM elements ('Record it', 'Zoomcorder', 'Would you like a copy?') that link to https://zoomcorder.com with the victim's meeting URL appended as …
6Obfuscation
medium
background.js (line 41)The Firebase init block, the message listener, and a setUninstallURL call are duplicated verbatim later in the file (lines 42-83 mirror lines 1-40), and a second, conflicting setUninstallURL ('/uninstall/zed') overwri…
URLs
56
IPv4
1
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

zoomcorder.com/uninstall/google-auto-smashhttps://zoomcorder.com/uninstall/google-auto-smash
zoocorder.firebaseio.com-https://zoocorder.firebaseio.com
www.w3.org/1999/02/22-rdf-syntax-nshttp://www.w3.org/1999/02/22-rdf-syntax-ns#
ns.adobe.com/xap/1.0/http://ns.adobe.com/xap/1.0/
ns.adobe.com/xap/1.0/mm/http://ns.adobe.com/xap/1.0/mm/
ns.adobe.com/xap/1.0/sType/ResourceEventhttp://ns.adobe.com/xap/1.0/sType/ResourceEvent#
ns.adobe.com/photoshop/1.0/http://ns.adobe.com/photoshop/1.0/
purl.org/dc/elements/1.1/http://purl.org/dc/elements/1.1/
openclipart.org/detail/165169/red-down-arrow-by-lpenzu%EF%BF%BDnGXtEXtCopyrightCC0https://openclipart.org/detail/165169/red-down-arrow-by-lpenzu�nGXtEXtCopyrightCC0
creativecommons.org/publicdomain/zero/1.0/%EF%BF%BD%EF%BF%BD%EF%BF%BDUPLTEhttp://creativecommons.org/publicdomain/zero/1.0/���UPLTE
Showing 1 to 10 of 60 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

10.1.1.46
IPv4
-
Showing 1 to 7 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.