Cisco Webex Extension
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 10 months ago
- Version
- v2.0.4
- Artifact
- SHA256 6D7…5A2
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This is the official Cisco Webex browser extension, published from the verified developer email [email protected]. With 23 million users and a clear purpose of joining Webex meetings in Chrome, this matches the legitimate enterprise communication tool.
The 11 high-severity findings all share critical red flags indicating false positives. Every single finding has file_path set to "unknown_file" rather than pointing to actual extension code. More importantly, all findings are from YARA rules with the "postinstall_" prefix: postinstall_crypto_operations, postinstall_obfuscation, postinstall_system_command, postinstall_file_manipulation, and postinstall_network_communication. According to CVEQ's documented false positive patterns, postinstall_* rules match basic Node.js patterns (fetch, exec, fs, crypto, process.env) and are classified as code-smell findings that should NEVER drive a verdict. The findings_summary confirms this, showing "code-smell":12 while "malware-signature":"0", indicating these are properly categorized as noise.
The single manifest finding for "nativemessaging" permission in manifest.json is expected and legitimate. Webex requires native messaging to communicate with the Webex desktop application for features like screen sharing, audio routing, and meeting controls. This is standard behavior for video conferencing extensions.
A skeptic might argue that 11 high-severity findings cannot all be false positives. However, the evidence contradicts this: (1) all findings reference "unknown_file" rather than actual extension files, (2) all use postinstall_* rule names that CVEQ explicitly documents as known false positives, (3) no actual malware signatures were detected (threat_indicators shows "malware-signature":"0"), (4) no suspicious network domains appear in the findings, and (5) the publisher is a verified Cisco corporate email address. The combination of verified publisher identity, legitimate product purpose, and findings that match documented false positive patterns makes this a clear case of analysis noise rather than actual threat.
The extension should be suppressed from further review as the findings are driven by known false positive YARA rules and analysis attribution errors.
Key Reasons
- Verified Cisco publisher email ([email protected])
- All malware findings reference unknown_file instead of actual extension code
- All high-severity findings use postinstall_* YARA rules documented as false positives
- 23 million users consistent with legitimate enterprise product
- Nativemessaging permission is expected for video conferencing extension
False Positive Considerations
- postinstall_* YARA rules matching Node.js patterns
- Findings attributed to unknown_file instead of actual extension code
- Code-smell findings misclassified as malware-signature
- High-severity scoring on known benign patterns
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 92%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Webex Calling for Chrome
[email protected]
Call with Jabber
[email protected]
Cisco Web Communicator
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer