Chrome Web Store
1Versions
1Code reviewed

No malware found

In code review

Our reviewer read this extension’s code and found no malicious behaviour. Review the permissions below before installing.

What our analysis found

OneGlass, used by 1,000 people, showed no malicious code in Extension Auditor's review. Our code review reported 1 finding (1 high), led by network interception. Its permissions mean it can read and change data on all websites and can observe network requests.

Key findings

  • high· network interception —The extension unconditionally strips Content-Security-Policy and X-Frame-Options response headers from every URL the browser visits, not just the extension's own CRM target domains. CSP prevents XSS exploitation on banking, healthcare, and other sensitive sites; X-Frame-Options prevents clickjacking. While the architectural motivation is to allow the OneGlass app to be embedded as an iframe inside CRM portals, applying the filter to <all_urls> rather than the declared CRM host patterns degrades browser-level security for all other sites the user opens during an active browser session.

This is a legitimate enterprise sales tool by Accenture (publisher email thomas.lamb@) for CRM integration across Salesforce, Dynamics, HubSpot, and other platforms. All data endpoints resolve to subdomains or known enterprise CRM SaaS providers; no covert exfiltration was found. The elevated ML score is driven by legitimate enterprise features: SignalR WebSocket connections, multiple OAuth flows (MSAL, RingCentral), webRequestBlocking for header manipulation to enable iframe embedding across CRM domains, and a large multi-file codebase. One genuine security concern exists: the extension strips Content-Security-Policy and X-Frame-Options headers from ALL URLs globally (:301-308), not just its target CRM domains, which weakens browser-level XSS and clickjacking protections site-wide — an architectural overshoot likely motivated by iframe embedding requirements.

OneGlass

OneGlass Chrome extension security report

ID: bbiedcdmgcgbkadgoakapajcgdaookjj

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Removed
Version
5.977.23342.4
Size
2.49 MB
Rating
2.4/5
Reviews
7
Users
1,000
Type
Extension
Updated
Dec 11, 2023
Category
Productivity Workflow
Price
Free
Featured
No
Visibility
Unlisted
Mature
No
By Google
No
Trusted
No
This publisherTrack record
2extensions
1 no longer listed
Scanned by Extension Auditor — Low RiskDevelopers: embed this badge to link to this report.

Publisher Contextual Analysis

Author
n3-one-glass
Country
US
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Address
3565 Piedmont Rd NE Atlanta, GA 30305-8202 US
Website
Visit
Extensions
2
Active
1
Obsolete
1
Listed
0
Unlisted
2
Users
1,578

Screenshots & videos

Screenshot 1
Screenshot 2

Install growth

Item
Type
Severity
Description
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestBlocking
Permission
Critical
This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
Dangerous Permission Combination
Risk Factor
Critical
This extension can intercept, modify, and block web requests in real-time.
identity
Permission
High
This permission accesses Chrome identity service and user information. Rated High because it can obtain OAuth tokens, access connected accounts, and impersonate the user in authenticated service.
identity.email
Permission
High
This permission directly accesses the user's email address. Rated High because it reveals personally identifiable information and can be used for tracking or targeting.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact• 15% increase: Older manifest version lacks modern security controls
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
Access to Sensitive Domains
Risk Factor
Medium
This extension requests access to sensitive domains: *://*.lightning.force.com/*, *://*.marketingautomation.services/*, *://app.hubspot.com/*
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
notifications
Permission
Low
This permission displays system notifications. Rated Low because it can only show user-visible notifications without accessing system data.
identity.launchWebAuthFlow
Permission
Unknown
No classification available for this permission.
  • 1 high

The file, code excerpt and explanation behind each finding are part of the full report. No conclusion has been withheld — only the evidence. The verdict above already reflects everything found here.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Provides an easy way for the BDRs to initiate phone calls.

Read the publisher’s full description

This is version 5.977.23342.4 uploaded on 12/10/2023. This application provides valuable features for a Sales, Service or Customer Success agent. One of the main benefits of using this application is the ease in which insights can be captured from customer interactions. The application provides a single presentation and interaction layer to access the CRM. Over time, it also aggregates insights and presents them to the agent for improved customer interactions. Other features include: - Integrated click-to-call - Efficient tracking for follow-ups - Goal tracking and measuring against team performance - Easy access to links and document that are helpful for the agent in their day-to-day tasks. - Capturing outcome of customer interactions. - Summary of daily activity performed.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
175
IPv4
2

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
5.977.23342.4
Latest
2.49 MBNo malware found0
e48cb8efc089e013bd679896717749375cdd41b129ffdca80428588bb559541a
Showing 1 to 1 of 10 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.