Chrome Web Store Verified

Cisco Webex Extension

by [email protected] · 22.0M users · 2.3 rating
5eb474b4-dd03-5981-a573-909c52f7eda7 | v2.0.4
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v2.0.4
Artifact
SHA256 6D7…5A2
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

72
Noisy-finding weight
x1.00
Publisher domain
cisco.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
24
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This is the official Cisco Webex browser extension, published from the verified developer email [email protected]. With 23 million users and a clear purpose of joining Webex meetings in Chrome, this matches the legitimate enterprise communication tool.

The 11 high-severity findings all share critical red flags indicating false positives. Every single finding has file_path set to "unknown_file" rather than pointing to actual extension code. More importantly, all findings are from YARA rules with the "postinstall_" prefix: postinstall_crypto_operations, postinstall_obfuscation, postinstall_system_command, postinstall_file_manipulation, and postinstall_network_communication. According to CVEQ's documented false positive patterns, postinstall_* rules match basic Node.js patterns (fetch, exec, fs, crypto, process.env) and are classified as code-smell findings that should NEVER drive a verdict. The findings_summary confirms this, showing "code-smell":12 while "malware-signature":"0", indicating these are properly categorized as noise.

The single manifest finding for "nativemessaging" permission in manifest.json is expected and legitimate. Webex requires native messaging to communicate with the Webex desktop application for features like screen sharing, audio routing, and meeting controls. This is standard behavior for video conferencing extensions.

A skeptic might argue that 11 high-severity findings cannot all be false positives. However, the evidence contradicts this: (1) all findings reference "unknown_file" rather than actual extension files, (2) all use postinstall_* rule names that CVEQ explicitly documents as known false positives, (3) no actual malware signatures were detected (threat_indicators shows "malware-signature":"0"), (4) no suspicious network domains appear in the findings, and (5) the publisher is a verified Cisco corporate email address. The combination of verified publisher identity, legitimate product purpose, and findings that match documented false positive patterns makes this a clear case of analysis noise rather than actual threat.

The extension should be suppressed from further review as the findings are driven by known false positive YARA rules and analysis attribution errors.

Key Reasons

  • Verified Cisco publisher email ([email protected])
  • All malware findings reference unknown_file instead of actual extension code
  • All high-severity findings use postinstall_* YARA rules documented as false positives
  • 23 million users consistent with legitimate enterprise product
  • Nativemessaging permission is expected for video conferencing extension

False Positive Considerations

  • postinstall_* YARA rules matching Node.js patterns
  • Findings attributed to unknown_file instead of actual extension code
  • Code-smell findings misclassified as malware-signature
  • High-severity scoring on known benign patterns

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 92%.

About This Extension

Cisco Webex web and video conferencing is an easy, cost-effective way to exchange ideas and information online with anyone, anywhere on any mobile device or video system. Accelerate decision-making, keep projects on track, and collaborate in real time with integrated audio, video, and content sharing, all in one meeting. Enhance engagement with a lifelike video experience, which rapidly builds relationships and trust, just like you would in person. Make connecting simple for smoother meetings so users can invite others to easily join with their own video system. From the proven industry leader in web and video conferencing, rely on secure, scalable Webex meetings from the global Cisco Collaboration Cloud.

Frequently Asked Questions