Caution required
Suspicious in code review (v5.977.23342.4)
Our reviewer found behaviour consistent with malware in version 5.977.23342.4, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.
What our analysis found
OneGlass Extension is rated caution by Extension Auditor. Our code review reported 3 findings (1 critical, 1 high, 1 medium), led by other. Its permissions mean it can inject scripts into pages.
Key findings
- critical· other —The extension strips `content-security-policy` and `x-frame-options` response headers from every URL the browser fetches, not just the declared CRM domains. Removing CSP globally eliminates inline-script protections on banking, email, and other sensitive sites, enabling XSS exploitation by any injected content. Removing X-Frame-Options globally eliminates clickjacking protection on all websites. Even if the developer's intent was to allow the extension's iframe injection on CRM pages, scoping to `<all_urls>` makes this a system-wide security downgrade for every site the user visits.
- high· other —The bundled (installed) manifest is Manifest V2 and includes `webRequest`, `webRequestBlocking`, and `<all_urls>`, none of which appear in the live CWS-published manifest (which is MV3 and lists only `identity`, `activeTab`, `notifications`, `scripting`, `storage`, `tabs`). Users who install from the Chrome Web Store see a narrower permission set than what actually runs — the installed extension has blocking network interception capability that the store listing does not disclose. This discrepancy between the installed and published manifest is itself a high-severity finding under the manifest mismatch check.
- medium· credential theft —A SalesLoft API Bearer token (`v2_ak_102653_…`) is hardcoded verbatim in the extension source. Because Chrome extension source is readable by any installed user, this credential is effectively public to every person who has the extension installed. An attacker with access to the token can query the SalesLoft API for data associated with the account, exfiltrate leads, or perform actions within the SalesLoft account. The token should be provisioned per-user via OAuth or fetched at runtime from the extension's backend after authentication.
OneGlass is a legitimate enterprise CRM-telephony tool, but three concrete security issues were found in the source code. Most critically, strips `content-security-policy` and `x-frame-options` response headers from ALL URLs (`<all_urls>`) in blocking mode — not scoped to the CRM integrations — weakening every website the user visits against XSS and clickjacking. Additionally, the bundled manifest is MV2 with `webRequest`, `webRequestBlocking`, and `<all_urls>` permissions, while the published CWS manifest shows MV3 without those permissions, meaning users believe they installed a less-capable extension than what is actually running. A hardcoded SalesLoft API Bearer token in is a credential exposure risk. The publisher (thomas.lamb@, verified Accenture) is credible and the CRM functionality is entirely coherent, arguing against intentional malice — but the global header-stripping and permission discrepancy are real harms that corroborate the ML flag rather than explain it away.
OneGlass Extension Chrome extension security report
ID: alkmghnpkmdnikkgpmbenchcdjfeomhi
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- n3-one-glass
- Privacy
- Privacy Policy
- Country
- US
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- No
- Mailbox exists
- Yes
- Address
- 3565 Piedmont Rd NE Atlanta, GA 30305-8202 US
- Website
- Visit
Email Change History
Screenshots & videos
Install growth
Sensitive Domain Access
This extension has access to the following sensitive domains:
- *://*.lightning.force.com/*
- *://*.marketingautomation.services/*
- *://*.hubspot.com/*
- *://amh.amazon.co.uk/*
Gain full insight into all external connections.
Upgrade for full visibility.
About this extension
Provides an easy way for the BDRs to initiate phone calls.
Read the publisher’s full description
This is version 6.0.40 PROD uploaded on 07/08/2025. This application provides valuable features for a Sales, Service or Customer Success agent. One of the main benefits of using this application is the ease in which insights can be captured from customer interactions. The application provides a single presentation and interaction layer to access the CRM. Over time, it also aggregates insights and presents them to the agent for improved customer interactions. Other features include: - Integrated click-to-call - Efficient tracking for follow-ups - Goal tracking and measuring against team performance - Easy access to links and document that are helpful for the agent in their day-to-day tasks. - Capturing outcome of customer interactions. - Summary of daily activity performed.
User reviews
Extension files
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
Code Diff
Compare extension code between any two versions.
0 changed files detected
No comparable text files found between these versions.
Gain full insight into all external connections.
Upgrade for full visibility.
Related extensions
More from n3-one-glass
- OneGlass1,000 users
Popular in Workflow & Planning
- Application Launcher For Drive (by Google)98,000,000 users
- Chrome Remote Desktop41,000,000 users
- Microsoft Single Sign On37,000,000 users
- PrinterLogic Extension v1.0.6.113,000,000 users
- MetaMask12,000,000 users