Chrome Web Store
50Versions
1Code reviewed

Caution required

Suspicious in code review (v5.977.23342.4)

Our reviewer found behaviour consistent with malware in version 5.977.23342.4, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

What our analysis found

OneGlass Extension is rated caution by Extension Auditor. Our code review reported 3 findings (1 critical, 1 high, 1 medium), led by other. Its permissions mean it can inject scripts into pages.

Key findings

  • critical· other —The extension strips `content-security-policy` and `x-frame-options` response headers from every URL the browser fetches, not just the declared CRM domains. Removing CSP globally eliminates inline-script protections on banking, email, and other sensitive sites, enabling XSS exploitation by any injected content. Removing X-Frame-Options globally eliminates clickjacking protection on all websites. Even if the developer's intent was to allow the extension's iframe injection on CRM pages, scoping to `<all_urls>` makes this a system-wide security downgrade for every site the user visits.
  • high· other —The bundled (installed) manifest is Manifest V2 and includes `webRequest`, `webRequestBlocking`, and `<all_urls>`, none of which appear in the live CWS-published manifest (which is MV3 and lists only `identity`, `activeTab`, `notifications`, `scripting`, `storage`, `tabs`). Users who install from the Chrome Web Store see a narrower permission set than what actually runs — the installed extension has blocking network interception capability that the store listing does not disclose. This discrepancy between the installed and published manifest is itself a high-severity finding under the manifest mismatch check.
  • medium· credential theft —A SalesLoft API Bearer token (`v2_ak_102653_…`) is hardcoded verbatim in the extension source. Because Chrome extension source is readable by any installed user, this credential is effectively public to every person who has the extension installed. An attacker with access to the token can query the SalesLoft API for data associated with the account, exfiltrate leads, or perform actions within the SalesLoft account. The token should be provisioned per-user via OAuth or fetched at runtime from the extension's backend after authentication.

OneGlass is a legitimate enterprise CRM-telephony tool, but three concrete security issues were found in the source code. Most critically, strips `content-security-policy` and `x-frame-options` response headers from ALL URLs (`<all_urls>`) in blocking mode — not scoped to the CRM integrations — weakening every website the user visits against XSS and clickjacking. Additionally, the bundled manifest is MV2 with `webRequest`, `webRequestBlocking`, and `<all_urls>` permissions, while the published CWS manifest shows MV3 without those permissions, meaning users believe they installed a less-capable extension than what is actually running. A hardcoded SalesLoft API Bearer token in is a credential exposure risk. The publisher (thomas.lamb@, verified Accenture) is credible and the CRM functionality is entirely coherent, arguing against intentional malice — but the global header-stripping and permission discrepancy are real harms that corroborate the ML flag rather than explain it away.

OneGlass Extension

OneGlass Extension Chrome extension security report

ID: alkmghnpkmdnikkgpmbenchcdjfeomhi

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Active
Version
6.0.53
Size
6.69 MB
Rating
1.0/5
Reviews
2
Users
578
Type
Extension
Updated
Sep 22, 2026
Category
Workflow & planning
Price
Free
Featured
No
Visibility
Unlisted
Mature
No
By Google
No
Trusted
No
This publisherTrack record
2extensions
1 no longer listed

Publisher Contextual Analysis

Author
n3-one-glass
Country
US
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Address
3565 Piedmont Rd NE Atlanta, GA 30305-8202 US
Website
Visit
Extensions
2
Active
1
Obsolete
1
Listed
0
Unlisted
2
Users
1,578

Email Change History

1 change
Oct 2, 2025
Domain changed

Screenshots & videos

Screenshot 1
Screenshot 2

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
identity
Permission
High
This permission accesses Chrome identity service and user information. Rated High because it can obtain OAuth tokens, access connected accounts, and impersonate the user in authenticated service.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
https://localhost:7215/*
Host
Medium
Host permission — access limited to this URL pattern.
https://apigatewayus-gcp.accenture.com/nextgenog/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.salesforce.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.visual.force.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.lightning.force.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.salesloft.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.powerbi.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.oceanengine.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.marketingautomation.services/*
Host
Medium
Host permission — access limited to this URL pattern.
*://apps.cisco.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://microsoft.service-now.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://icp.wdf.sap.corp/*
Host
Medium
Host permission — access limited to this URL pattern.
*://harmony-insight.enter.sap/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.hubspot.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://app.salesloft.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://mmm.oceanengine.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://chp.tbe.taleo.net/*
Host
Medium
Host permission — access limited to this URL pattern.
*://amh.amazon.co.uk/*
Host
Medium
Host permission — access limited to this URL pattern.
Access to Sensitive Domains
Risk Factor
Medium
This extension requests access to sensitive domains: *://*.lightning.force.com/*, *://*.marketingautomation.services/*, *://*.hubspot.com/*, *://amh.amazon.co.uk/*
notifications
Permission
Low
This permission displays system notifications. Rated Low because it can only show user-visible notifications without accessing system data.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Provides an easy way for the BDRs to initiate phone calls.

Read the publisher’s full description

This is version 6.0.40 PROD uploaded on 07/08/2025. This application provides valuable features for a Sales, Service or Customer Success agent. One of the main benefits of using this application is the ease in which insights can be captured from customer interactions. The application provides a single presentation and interaction layer to access the CRM. Over time, it also aggregates insights and presents them to the agent for improved customer interactions. Other features include: - Integrated click-to-call - Efficient tracking for follow-ups - Goal tracking and measuring against team performance - Easy access to links and document that are helpful for the agent in their day-to-day tasks. - Capturing outcome of customer interactions. - Summary of daily activity performed.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
252
IPv4
3

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
6.0.53
Latest
6.69 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
6.0.52
6.68 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
6.0.51
6.68 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
6.0.50
6.66 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
6.0.49
6.66 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
6.0.48
6.65 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
6.0.47
6.65 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
6.0.46
6.65 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
6.0.45
6.65 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
6.0.44
6.65 MBNot scanned—
802315681facfdead4c971deda2b00c90c51a114b123ce419ba43866fca6f4ac
Showing 1 to 10 of 50 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

More from n3-one-glass

Popular in Workflow & Planning