Chrome Web Store Verified

Adobe Photoshop

by [email protected] · 800.0K users · 3.8 rating
f65fa72b-55a9-5c06-8abe-68036dabb698 | v1.0.24
53/ 100
MEDIUM risk
No change since v1.0.17
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (53/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v1.0.24
Artifact
SHA256 0C6…F95
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

17 detail rows

Publisher Evidence

Low

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

84
Noisy-finding weight
x1.00
Publisher domain
adobe.com
Trusted match
Store verification signal
Limited signal
Limited
Extension portfolio
25
Portfolio

12 evidence rows available.

Finding Categories

16
Network

Requested Permissions

6 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
tabs
Medium
storage
Low
contextMenus
Low
sidePanel
Low
declarativeNetRequest
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension is published by Adobe using the verified email address [email protected], which is a strong indicator of legitimacy. The extension description states it provides background removal and color adjustment features with access to Photoshop web, consistent with Adobe's product line.

The security scan identified 11 findings, all classified as medium severity. There are zero malware signatures, zero obfuscation detections, and zero suspicious domain IoCs in the entire extension. This absence of actual malicious indicators is the most important signal.

The single manifest finding (MANIFEST-SENSITIVE-PERM-TABS in manifest.json) flags the tabs permission as potentially sensitive. However, this permission is legitimate for an extension that modifies web pages and integrates with Photoshop web functionality. The permission matches the extension's stated purpose.

All 10 network findings are generic fetch and socket_io calls located in bundled chunk files: chunks/storage-xiDPc5Q0.js, background.js, chunks/editor-B8Unbvnx.js, chunks/newrelic-CY7kDpVp.js, and chunks/aggregate-base-C1YnNr2T.js. These are webpack bundle outputs, which is standard for modern JavaScript applications. The network calls represent normal communication with Adobe's services for the extension's functionality. Notably, none of these findings reference suspicious domains like query., search., or unknown third-party servers.

The file naming convention (chunks/* with hash identifiers) confirms this is a properly bundled application. The presence of newrelic-CY7kDpVp.js indicates New Relic monitoring, a legitimate enterprise analytics service commonly used by large companies like Adobe.

A skeptic might argue that 700,000 users and network activity could mask malicious behavior. However, the evidence contradicts this: zero malware signatures, zero obfuscation, zero suspicious domains, and a verified Adobe publisher email. If this were malicious, we would expect at least one of these critical indicators. The network findings are generic patterns that fire on any extension making HTTP requests, which is necessary for a cloud-connected Photoshop tool.

This extension demonstrates the expected behavior of a legitimate Adobe product: proper bundling, verified publisher identity, and network calls consistent with its described functionality. The findings are false positives driven by the scanner's inability to distinguish legitimate network activity from malicious exfiltration in bundled code.

Key Reasons

  • Verified Adobe publisher ([email protected])
  • Zero malware signatures detected
  • Zero obfuscation findings
  • Zero suspicious domain IoCs
  • Network activity consistent with described functionality

False Positive Considerations

  • Bundled webpack chunks triggering network findings
  • Generic fetch/socket_io patterns in legitimate code
  • Enterprise analytics library (New Relic) in bundle

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

Chrome version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
53
Change since first
-4
Change from previous
No change
Versions:
First analyzed version
1.0.14
Mar 12, 2026
Risk range
53 to 58
Across analyzed versions
Latest analyzed version
1.0.24
Sep 24, 2026
Selected version
medium
Version
v1.0.24
1 weeks ago
Risk score
53
Findings
17
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Collecting inspiration for your next project? Skip downloading images and then uploading them again just to edit. The Photoshop extension lets you choose an image and easily edit it right in your browser, no extra software needed. Here’s what you can do: • Collect images – Right-click an image or select the Photoshop badge to add it to your collection • Remove backgrounds – Erase an image’s background in seconds • Make adjustments – Fine-tune brightness, contrast, saturation, and more with precision controls • Crop to social presets – Create custom sizes and instantly crop images to Instagram, Facebook, or YouTube • Download – Export your edited images directly to your device Perfect for: Content creators, designers, marketers, and anyone who needs quick, powerful image edits. We’re just getting started: This extension will continue to grow, bringing new tools and improvements designed to make editing in your browser faster and more powerful. Terms & Conditions: Your use of this application is governed by the Adobe General Terms of Use (http://www.adobe.com/go/terms_en) and the Adobe Privacy Policy (http://www.adobe.com/go/privacy_policy_en) and any successor versions thereto.

Frequently Asked Questions