You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Awesome Screenshot Safari Extension, injecting code in to web pages

Hi


I'm not sure if Apple are aware of this but I've notice some very dodgy activity from one of Safari's top rated extensions injecting adverts/price comparison code into the header of web pages. The extension is 'Awesome Screenshot' which is very highly rated on the Apple Extensions site.


It is adding "prestosavings.js" script in to the page. I develop websites so look through code a lot and I couldn't figure out where this was coming from after pulling apart a site looking for this assuming it was a malware issue on the site itself. I discovered that it was the Awesome Screenshot after tracing it back and noticed the following 'Enable price comparation' checkbox has appeared with no warning.


User uploaded file

If you uncheck this box, the code is still injected into the page. I have now deleted this extension, but Apple, you really need to check into this... At no point did I agree to this added feature and it wasn't pointed out as a new feature when the extension was updated.


I will think again about using ANY extensions you feature in the future.

Posted on Jul 11, 2014 3:58 AM

Reply
8 replies

Jan 13, 2015 9:27 AM in response to Carolyn Samit

Hy Carolyn,


Six months later I run into the same issue. Only this time this particular extension is sending my browser behavior to third parties. I can clearly see in my Web Inspector that a POST request is being done to the Presto Savings ad network, that includes the hostname of sites I visit. Also see this tweet by someone else:


https://twitter.com/labemi/status/526445876689260544


Please pull this extension from the Extension Gallery a.s.a.p: https://extensions.apple.com/details/?id=com.diigo.safari.awesomeScreenshot-5DXN M3K2CT

Awesome Screenshot Safari Extension, injecting code in to web pages

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.