Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

High-Custom New Tab

abnhonfioiokelhdappjknfaannlncac
Risk Score
7.19
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 20,000
Rating 4.2
Last updated 2022-09-09 (45 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@unicore-alliance.net
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Severely stale angular@1.5.5 with 2 high-severity CVEs and 7 moderate CVEs (XSS, prototype pollution, ReDoS); no fix path.
  • No CSP and no-fix angular in a DOM-manipulation lib triggers ×1.5 CVE amplifier; final CVE pillar capped at 10.0.
  • Extension has not been updated in 45 months; abandoned with known-vulnerable bundled libraries.
  • Privacy policy is Google's generic account policy — scope_extension==false, data_collection==true, third_party_sharing==true → +10.0 Privacy pillar.
  • Developer domain unicore-alliance.net does not resolve; no developer name listed; no meaningful accountability.

Evidence

  • cve_angular_high crx angular@1.5.5: CVE-2024-21490 (high, no fix), CVE-2019-10768 (high, fixed in 1.7.9) — prototype pollution and ReDoS.
  • cve_angular_moderate_mass crx angular@1.5.5: 7 moderate CVEs (XSS via JSONP, JQLite XSS, multiple ReDoS, CVE-2022-25869); several have no fix.
  • cve_jquery_moderate crx jquery@3.2.1: 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed in 3.4.0/3.5.0.
  • no_csp_dom_lib_cve_amplifier crx csp_present==false + high/moderate CVEs in angular (DOM-manipulation lib) → ×1.5 CVE amplifier applied.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension==false, data_collection==true, third_party_sharing==true.
  • developer_domain_does_not_resolve api unicore-alliance.net does not resolve; developer_name is empty; no verified accountability.
  • stale_45_months store Last updated September 2022; 45 months since update with vulnerable libraries and MV3 newtab override.
  • code_eval_function_constructor crx eval_user_input + function_constructor signals in plugins.min.js (angular internals); no CSP to mitigate.

CVE Exposures (14)

CVELibrarySeverity Fixed inSummary
angular@1.5.5 angular@1.5.5 moderate 1.6.0 Cross-Site Scripting via JSONP
CVE-2023-26117 angular@1.5.5 moderate angular vulnerable to regular expression denial of service via the $resource ser
CVE-2023-26116 angular@1.5.5 moderate angular vulnerable to regular expression denial of service via the angular.copy(
CVE-2024-21490 angular@1.5.5 high angular vulnerable to super-linear runtime due to backtracking
CVE-2019-10768 angular@1.5.5 high 1.7.9 angular Prototype Pollution vulnerability
CVE-2025-0716 angular@1.5.5 low AngularJS improperly sanitizes SVG elements
CVE-2024-8372 angular@1.5.5 low AngularJS allows attackers to bypass common image source restrictions
CVE-2020-7676 angular@1.5.5 moderate 1.8.0 Angular vulnerable to Cross-site Scripting
CVE-2024-8373 angular@1.5.5 low AngularJS allows attackers to bypass common image source restrictions
CVE-2022-25869 angular@1.5.5 moderate Angular (deprecated package) Cross-site Scripting
CVE-2023-26118 angular@1.5.5 moderate angular vulnerable to regular expression denial of service via the <input type="
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • chrome_url_overrides.newtab medium Replaces new tab page; primary vector for search monetization and user tracking.

Pillar Scores

Permissions3.00
Reputation6.00
Network4.50
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality5.50
CVE Exposure10.00

Scoring History

v3.6 7.19 High block 2026-06-16
v3.4-rev 4.76 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA 8d82fefae215…
Force block — not fired
Score recovered no
Elapsed 41.0s