Chrome Web Store Verified

Citrix Workspace

by [email protected] · 3.2 rating
cd46a39a-16fc-58c4-bc18-b060294fa09e | v26.3.50.60
100/ 100
CRITICAL risk
+15 since v26.3.1.3
Risk verdict
Do not install

Score-based assessment (critical risk, 100/100). No analyst review available.

Analysis record

Analysed
3 weeks ago
Version
v26.3.50.60
Artifact
SHA256 8E5…4A9
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 390 · highest severity first

YARA Rule Matches

14 rules
SeverityRuleHitsFilesMetadata
HIGHhex script 2
ChromeAppUI/js/Utils.jsChromeAppUI/js/Main.js
FP 20%
LOWpostinstall persistence mechanism 18
locales/fr.jsThirdPartyLibrary/WASM/SecureICA/secureIca.wasmlocales/zh-tw.js +15 more
-
LOWWeakSSLTLSProtocolsShouldNotBeUsed 2
ThirdPartyLibrary/WASM/edt.wasmThirdPartyLibrary/WASM/AOT/libctxlogfileservice.wasm
-
LOWcredential env files 3
ThirdPartyLibrary/WASM/edt.wasmThirdPartyLibrary/WASM/AOT/libctxlogfileservice.wasmsrc/citrixHTML5Launcher.js
-
LOWpostinstall file download 69
locales/nl.jsThirdPartyLibrary/WASM/USBPolicyLib/USBPolicyManager.jsThirdPartyLibrary/WASM/GenScan/GenScan.js +66 more
-
LOWNoUseEval 5
ThirdPartyLibrary/PCSC/scard.jsThirdPartyLibrary/Compiled/jpeg-1.5.0.jsThirdPartyLibrary/Compiled/vorbis.js +2 more
-
LOWNoUseWeakRandom 2
cwa-ui-lib/js/cwa-ui-lib-main.b4ef0ca1fb4a378c1a91.jscwa-ui-lib/js/cwa-ui-lib-react.8d431bd2b91ef6058272.js
-
LOWspyeye 1
ThirdPartyLibrary/WASM/sampleWASM.wasm
-
LOWDebuggerStatementsShouldNotBeUsed 1
ThirdPartyLibrary/PDFJS/web/viewer.css
-
LOWpostinstall file manipulation 73
src/Business/ConfigServiceFilesWorker.jsThirdPartyLibrary/WASM/CGP/V1/CgpClientV1.jsThirdPartyLibrary/WASM/CSI/csi.js +70 more
-
LOWpostinstall network communication 353
Shared/PAL/LocalWebStorage/WebLocalStorage_26.3.50.60.jssrc/Business/USBEngineFiles26.3.50.60.jssrc/Business/AudioInCoordinatorWorker_26.3.50.60.js +350 more
-
LOWpostinstall system command 2
Common/BaseCitrixAnalytics.jsresources/fonts/citrixsans/citrixsans-italic.ttf
-
LOWpostinstall obfuscation 71
ThirdPartyLibrary/WASM/GenScan/GenScan.jsThirdPartyLibrary/WASM/CSI/csi.jsThirdPartyLibrary/WASM/SelfieSegmentation/selfie_segmentation_solution_simd_wasm_bin.wasm +68 more
-
LOWpostinstall registry modification 8
ThirdPartyLibrary/WASM/SelfieSegmentation/selfie_segmentation_solution_wasm_bin.jsThirdPartyLibrary/WASM/SelfieSegmentation/selfie_segmentation_solution_wasm_bin.wasmThirdPartyLibrary/WASM/SelfieSegmentation/selfie_segmentation_solution_simd_wasm_bin.js +5 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

419 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

42
Noisy-finding weight
x1.00
Publisher domain
cloud.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
8
Portfolio

11 evidence rows available.

Finding Categories

2
Malware Signatures
367
Obfuscation
23
Network
419
IoC Indicators

YARA Rules Matched

14 rules(610 hits)
hex script postinstall persistence mechanism WeakSSLTLSProtocolsShouldNotBeUsed credential env files postinstall file download NoUseEval NoUseWeakRandom spyeye DebuggerStatementsShouldNotBeUsed postinstall file manipulation postinstall network communication postinstall system command postinstall obfuscation postinstall registry modification

Requested Permissions

34 permissions
http://*/*
Dangerous
https://*/*
Dangerous
webRequest

Intercept, modify, and block all network requests

High
clipboardRead

Read data from your clipboard

High
identity

Access your identity and sign-in tokens

High
idle
Low
clipboard
Low
clipboardWrite
Low
notifications
Low
storage
Low
identity.email
Low
webview
Low
system.network
Low
app.window.fullscreen.overrideEsc
Low
serial
Low
geolocation
Low
power
Low
gcm
Low
usb
Low
videoCapture
Low
audioCapture
Low
enterprise.deviceAttributes
Low
enterprise.hardwarePlatform
Low
app.window.shape
Low
contextMenus
Low
system.display
Low
alwaysOnTopWindows
Low
alarms
Low
networking.onc
Low
platformKeys
Low
printing
Low
documentScan
Low
system.cpu
Low
system.memory
Low

Security Analysis Summary

Security Analysis Overview

Citrix Workspace is a Chrome Web Store extension published by [email protected]. Version 26.3.50.60 has been analyzed by the Risky Plugins security platform, receiving a risk score of 100/100 (CRITICAL risk) based on 2095 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • High: 356 finding(s)
  • Medium: 455 finding(s)
  • Low: 1284 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Citrix Workspace is published by [email protected] on the Chrome Web Store marketplace.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Chrome version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
No change
Change from previous
+15
Versions:
First analyzed version
25.11.0.68
Jan 21, 2026
Risk range
85 to 100
Across analyzed versions
Latest analyzed version
26.3.50.60
Aug 24, 2026
Selected version
critical
Version
v26.3.50.60
3 weeks ago
Risk score
100
Findings
2096
Change vs previous
+15

Pick any point on the chart to explore that version's code below.

About This Extension

This release is compatible with ChromeOS versions 149, 150, and 151. What’s new in 2603.50 Enhanced in-session reconnection experience - Fixed issues - When you use Microsoft Azure AD (Microsoft Entra ID) or Okta as your identity provider, Citrix Workspace app for ChromeOS single sign-on (SSO) to the store might fail. In such a case, the Citrix Workspace app for ChromeOS prompts you to sign-in again to the store instead of authenticating you silently. [CVADHELP-33766] - When you are in a multi-monitor Microsoft Teams-optimized session with an external monitor set as the primary display, the screen content shared by other participants might display at an incorrect position. [CVADHELP-34174] - When you use Citrix Workspace app for ChromeOS on ChromeOS 152 and later, the Close (X) button in the Connection Center window might not respond. So even if you click the close button, the window doesn’t close. [RFHTMCRM-19180] - The Citrix Workspace app for ChromeOS sessions might revert from fullscreen or multimonitor mode to windowed mode after locking and unlocking the Chromebook devices. [CVADHELP-33425] - During a desktop session, the mouse cursor might intermittently stop responding, failing to update its shape (for example, the mouse cursor remains an arrow instead of changing to a text cursor). [CVADHELP-33365] - The Auto-fit Screen (Fit_To_Window) setting, configured through Global App Configuration Service (GACS), might not persist when a session reconnects. This causes sessions to reset to default Device Pixel Ratio (DPR) mode. [CVADHELP-33365] - When you use Client Drive Mapping (CDM) to map files or folders within Citrix Workspace app for ChromeOS, some files might be missing in the mapped network drive. [CVADHELP-33220] - When you try to create a file using the Windows Save dialog on a drive that Client Drive Mapping (CDM) maps in Citrix Workspace app for ChromeOS session, the file creation might fail. [CVADHELP-32584] - Known issues - YubiKey is not usable in Citrix Session after redirection through USB. To use YubiKey through USB redirection, split the device and auto-redirect only the HID interface instead of the smart card interface. [CVADHELP-33417] Recommendations and Notes: • Starting with the version 2202 (22.2.1.8), only valid JSON is honored for pushing the configuration to Citrix Workspace app for Chrome OS. Do the following: • Verify the configuration JSON using https://jsonlint.com/. Follow the steps mentioned in Get started[https://docs.citrix.com/en-us/citrix-workspace-app-for-chrome/get-started.html] page to update: - Google Policy - web.config - default.ica - configuration.js • We recommend using Configuration utility tool[https://docs.citrix.com/en-us/citrix-workspace-app-for-chrome/google-policies.html] to generate valid JSON settings to customize Citrix Workspace app for Chrome OS using: - configuration.js - web.config - default.ica - Google Policy • For more information, see Knowledge center article https://support.citrix.com/article/CTX229141. • If you are on HTTP-based stores, for a secure context, we recommend that you transition to HTTPS-based stores. For more information, see HTTPS. • To avoid any impact of Chrome OS version 96 update on Microsoft Teams functioning, do the following before you update the Chrome OS: • For a repackaged Citrix Workspace app for Chrome OS users, see Knowledge Center article https://support.citrix.com/article/CTX331648 and implement the steps. • For a version of Citrix Workspace app 2110 and earlier, see Knowledge Center article https://support.citrix.com/article/CTX331653. For more information about Citrix Workspace app, visit https://docs.citrix.com/en-us/citrix-workspace-app-for-chrome/about.html

Frequently Asked Questions