Chrome Web Store
28Versions
6Code reviewed

Caution required

Suspicious in code review (v2.0.32)

Our reviewer found behaviour consistent with malware in version 2.0.32, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

28 indicators in this extension

28 indicators
6 versions analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

What our analysis found

Read Aloud TTS: Text to Speech AI Voice Generator, used by 600,000 people, is rated caution by Extension Auditor. Our code review reported 2 findings (2 medium), led by unauthorized data collection. Its permissions mean it can read and change data on all websites and can inject scripts into pages.

Key findings

  • Medium

    Unauthorized Data Collection

    Every navigation in every tab - not only pages the user asks to be read - is reported to [domain withheld] with the full URL including query string, the tab's previous URL as referrerUrl (t4 at:22434 keeps a 100-entry per-tab referrer chain in chrome.storage.local), a persistent per-install UUID (), and the page's HTTP status, method and content-type captured by the extension's only webRequest listener at:22539 - a linkable browsing history whose sole consumer is this beacon. It is gated on the opt-in contentOptimization flag set by the consent screen, but that screen describes the data as 'anonymized information about the pages you visit', which the persistent instanceId and full URLs contradict, and the Chrome Web Store listing declares no data collection at all - so neither Google nor the user is told what is actually sent. The server does return a per-site parsing mode that the content script consumes, giving the flow a functional pretext, but that lookup is only needed when TTS is invoked, not on every page load; the publisher removed the whole mechanism and the webRequest permission in 2.0.40.

  • Medium

    Obfuscation

    The browsing-history payload above is AES-GCM encrypted with a 16-byte key hardcoded in the shipped bundle ('aB3dE5gH7jK9mN2p') and base64-wrapped as 'enRequest' before being POSTed. The request already travels over HTTPS to the publisher's own server and the key ships with every copy of the extension, so this adds no confidentiality against any attacker; its only practical effect is to keep the URL / referrer / device-ID payload unreadable to store reviewers and to anyone inspecting the extension's own traffic. Encrypting collected user data under an embedded key is deliberate concealment of the data flow rather than transport security, and it is what turns an otherwise arguable telemetry design into a finding.

Analyst notes

NOTE ON SOURCE: the supplied bundle at contained only 8 files and was missing, and the JS (per); I reviewed the complete 2.0.32 source unzipped from the stored CRX at /[domain withheld], so findings cite line numbers from that copy. This is a real TTS product and there is no malware: every destination across all 3.3 MB of JS is first-party ([domain withheld]} ->,,,,) plus one self-hosted Sentry DSN; there is no eval, no new Function, no chrome.cookies, no document.cookie read, no remote script loading and no credential harvesting. scripting.executeScript only injects the bundled behind an idempotency check and an explicit deny-list of::: URLs, and is driven by a file-picker onChange handler. What does not fit the product is:22467 (r4): on every tabs.onUpdated 'loading' event for any http(s) URL it POSTs the full targetUrl, the tab's previous URL as referrerUrl, a persistent crypto.randomUUID instanceId and webRequest-harvested response metadata to, AES-GCM-encrypted under a key hardcoded in the bundle (:22396). It is genuinely opt-in - i4 (:22495) gates it on chrome.storage.local contentOptimization, only the popup's Agree button writes it true, and the onMessageExternal handler map exposed to [domain withheld] is auth-only (AUTH_CREATE_SITE_HANDOFF / AUTH_HAS_EXTENSION_SESSION / AUTH_HANDOFF / AUTH_LOGOUT), so there is no silent enable path - but the consent text calls it 'anonymized' while the payload carries a persistent device ID and full URLs, the CWS listing declares no data collection at all, and the embedded-key encryption exists only to hide the payload. Contradicting the ML score: chrome-stats likelihood, featured, Google trusted-publisher badge, and the publisher removed webRequest and the entire beacon in (2.1.5's has no and actively deletes the legacy 'optimization-rules-v1-storage' and 'tabs' keys) - i.e. they walked this back themselves. Also correcting the inputs: the permhash cluster is not corroboration, because all four '100% malware' members are versions of this same extension ID (verified by psql), and 'whatsapp' appears 0 times in all five bundles, so the [domain withheld] WhatsApp-spamware article in the internal notes is not a fit for this code. The published-manifest summary (unlimitedStorage, no, has_content_scripts, web_accessible_resources '*') matches this extension's own 1.1.6-1.1.9 builds, not 2.0.32 or any later stored build, so that mismatch is a stale listing snapshot in our data rather than a covert divergence.

Read Aloud TTS: Text to Speech AI Voice Generator

Read Aloud TTS: Text to Speech AI Voice Generator Chrome extension security report

ID: npdkkcjlmhcnnaoobfdjndibfkkhhdfn

Extension Info & Metadata

Status
Active
Version
2.1.13
Size
0.98 MB
Rating
4.3/5
Reviews
3,200
Users
600,000
Type
Extension
Updated
Oct 5, 2026
Category
Accessibility
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
1extension
All still listed

Publisher Contextual Analysis

Trusted
Author
readaloud.net
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Users
600,000

Screenshots & videos

Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4
Screenshot 5
Screenshot 6
Screenshot 7
Screenshot 8
Screenshot 9

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
offscreen
Permission
High
This permission creates hidden browser documents with full DOM access. Rated High because it can run background operations invisibly, potentially executing malicious code without user awareness.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
tts
Permission
Low
This permission enables text-to-speech functionality. Rated Low because it can only convert visible text to speech without accessing sensitive data.
ttsEngine
Permission
Low
This permission implements a text-to-speech engine. Rated Low because it only processes text for speech conversion without storing or transmitting data.
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
sidePanel
Permission
Low
This permission adds custom panels to the browser interface. Rated Low because it only affects browser UI elements and cannot access page content.

28 indicators in this extension

28 indicators
6 versions analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

About this extension

Text to Speech (TTS) reads aloud text, PDFs & e-books with natural voices.

Read the publisher’s full description

Create high-quality text-to-speech of web pages and specific articles. Free. No registration. Text to speech - read aloud web-page articles, books, and PDF files. Generated speech can be easily modified (adjust tone, control voice or volume) TTS for generating voiceover with customizable speech and text overlays. Create a complete webpage TTS narration or select specific sections with an ability to edit, and listen the audio on your PC. The app runs directly in your browser, saving you time. Simply click the extension icon to choose between all text voice synthesis or a selected section. You won't strain your eyes reading large text or small fine print. Why waste time when all you need is text to speech? Our tool combines advanced text-to-speech (TTS) and summarization functionalities to provide a complete solution for both auditory and visual content consumption. Want to read your text aloud for cases like learning classwork, reading technical documentation, or listening to articles? Here are the reasons to choose TTS Text to Speech: ✔ Text to Speech conversion on multiple languages; ✔ Text to Speech male or female voices; ✔ Customizable voice settings and speed; ✔ Read aloud any webpage or document; ✔ Compatibility with additional file formats such as PDF and eBooks; ✔ Natural-sounding voice generation; ✔ Read offline files using built-in browser text-to-speech; ✔ No login or registration required; ✔ Generate summaries of YouTube videos, PDFs, and web articles. Open any webpage you want to listen to (or upload any document), then click extension icon, select "Play", and listen as text-to-speech engine reads the selected text, pause, rewind, or fast forward using the on-screen controls that appear once TTS starts reading. Notes Reload page after installing extension before using text-to-speech (Chrome loads extension on every page). Text to Speech TTS extension is free and easy to use. If you find it helpful, please give us 5 stars!

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
28

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

28 indicators in this extension

28 indicators
6 versions analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe
Version
Size
Verdict
Findings
Permhash
2.1.13
Latest
0.98 MBNot scanned—
d02e77158fc8f6016a0ebd467cd4a858853fc3c8c20ac6a9e623d5550b22149f
2.0.9
2.92 MBNot scanned—
d02e77158fc8f6016a0ebd467cd4a858853fc3c8c20ac6a9e623d5550b22149f
2.0.12
1.58 MBNo malware found0
47e4d8c246370f594d2550ae2efbc27849af0bd5a13cf310f510cfaf48818601
2.1.5
0.94 MBNot scanned—
d02e77158fc8f6016a0ebd467cd4a858853fc3c8c20ac6a9e623d5550b22149f
2.0.40
1.39 MBNot scanned—
d02e77158fc8f6016a0ebd467cd4a858853fc3c8c20ac6a9e623d5550b22149f
2.0.32
1.67 MBCaution0
47e4d8c246370f594d2550ae2efbc27849af0bd5a13cf310f510cfaf48818601
2.0.28
1.66 MBMalicious0
47e4d8c246370f594d2550ae2efbc27849af0bd5a13cf310f510cfaf48818601
2.0.19
1.60 MBNot scanned—
47e4d8c246370f594d2550ae2efbc27849af0bd5a13cf310f510cfaf48818601
2.0.3
1.94 MBNot scanned—
d02e77158fc8f6016a0ebd467cd4a858853fc3c8c20ac6a9e623d5550b22149f
2.0.0
1.59 MBNot scanned—
d02e77158fc8f6016a0ebd467cd4a858853fc3c8c20ac6a9e623d5550b22149f
Showing 1 to 10 of 30 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

Popular in Accessibility