High-Custom New Tab
abnhonfioiokelhdappjknfaannlncac
Risk Score
7.19
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Severely stale angular@1.5.5 with 2 high-severity CVEs and 7 moderate CVEs (XSS, prototype pollution, ReDoS); no fix path.
- No CSP and no-fix angular in a DOM-manipulation lib triggers ×1.5 CVE amplifier; final CVE pillar capped at 10.0.
- Extension has not been updated in 45 months; abandoned with known-vulnerable bundled libraries.
- Privacy policy is Google's generic account policy — scope_extension==false, data_collection==true, third_party_sharing==true → +10.0 Privacy pillar.
- Developer domain unicore-alliance.net does not resolve; no developer name listed; no meaningful accountability.
Evidence
- cve_angular_high crx angular@1.5.5: CVE-2024-21490 (high, no fix), CVE-2019-10768 (high, fixed in 1.7.9) — prototype pollution and ReDoS.
- cve_angular_moderate_mass crx angular@1.5.5: 7 moderate CVEs (XSS via JSONP, JQLite XSS, multiple ReDoS, CVE-2022-25869); several have no fix.
- cve_jquery_moderate crx jquery@3.2.1: 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed in 3.4.0/3.5.0.
- no_csp_dom_lib_cve_amplifier crx csp_present==false + high/moderate CVEs in angular (DOM-manipulation lib) → ×1.5 CVE amplifier applied.
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension==false, data_collection==true, third_party_sharing==true.
- developer_domain_does_not_resolve api unicore-alliance.net does not resolve; developer_name is empty; no verified accountability.
- stale_45_months store Last updated September 2022; 45 months since update with vulnerable libraries and MV3 newtab override.
- code_eval_function_constructor crx eval_user_input + function_constructor signals in plugins.min.js (angular internals); no CSP to mitigate.
CVE Exposures (14)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| angular@1.5.5 | angular@1.5.5 | moderate | 1.6.0 | Cross-Site Scripting via JSONP |
| CVE-2023-26117 | angular@1.5.5 | moderate | — | angular vulnerable to regular expression denial of service via the $resource ser |
| CVE-2023-26116 | angular@1.5.5 | moderate | — | angular vulnerable to regular expression denial of service via the angular.copy( |
| CVE-2024-21490 | angular@1.5.5 | high | — | angular vulnerable to super-linear runtime due to backtracking |
| CVE-2019-10768 | angular@1.5.5 | high | 1.7.9 | angular Prototype Pollution vulnerability |
| CVE-2025-0716 | angular@1.5.5 | low | — | AngularJS improperly sanitizes SVG elements |
| CVE-2024-8372 | angular@1.5.5 | low | — | AngularJS allows attackers to bypass common image source restrictions |
| CVE-2020-7676 | angular@1.5.5 | moderate | 1.8.0 | Angular vulnerable to Cross-site Scripting |
| CVE-2024-8373 | angular@1.5.5 | low | — | AngularJS allows attackers to bypass common image source restrictions |
| CVE-2022-25869 | angular@1.5.5 | moderate | — | Angular (deprecated package) Cross-site Scripting |
| CVE-2023-26118 | angular@1.5.5 | moderate | — | angular vulnerable to regular expression denial of service via the <input type=" |
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- chrome_url_overrides.newtab medium Replaces new tab page; primary vector for search monetization and user tracking.
Pillar Scores
Permissions3.00
Reputation6.00
Network4.50
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality5.50
CVE Exposure10.00
Scoring History
| v3.6 | 7.19 | High | block | 2026-06-16 |
| v3.4-rev | 4.76 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
8d82fefae215…
Force block
— not fired
Score recovered
no
Elapsed
41.0s