Rabby Wallet
acmacodkjbdgmoleebolmdjonilkdbch
Risk Score
4.98
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: arbitrary code execution); version unpatched.
- Privacy policy on debank.com does not scope to this extension and admits data collection without retention disclosure.
- Uninstall URL hijack detected; destination not captured but flag is authoritative.
- Multiple new Function() constructors in background.js and offscreen.js alongside <all_urls> host access.
- react@16.13.1 (below 16.4 threshold) bundled with underscore CVEs and CSP present but DOM-XSS sink in content-script.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed_in 1.12.1. Library not updated.
- high_cve_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8.
- privacy_policy_inadequate store Policy at debank.com: fetched=true, scope_extension=false, data_collection=true, retention=false, third_party_silence=true.
- uninstall_url_hijack crx uninstall_url_hijack=true; chrome.runtime.setUninstallURL() points to third-party destination.
- function_constructor_multi crx new Function() in background.js, offscreen.js, and two Trezor vendor files. Dynamic code execution surface.
- dom_xss_sink crx innerHTML on user-controlled variable in content-script.js injected on all URLs.
- host_permission_all_urls manifest <all_urls> host permission with broad content_scripts_matches including http://*/* and https://*/*.
- verified_publisher_no_developer_name store verified_publisher=true but developer_name is empty string; email hi@rabby.io on rabby.io domain resolves.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- scripting medium Can inject JS into pages; paired with <all_urls> host permission raises risk.
- storage low Standard key-value storage; expected for a wallet.
- unlimitedStorage low Removes storage quota; minor risk for wallet caching.
- alarms low Periodic background tasks; low standalone risk.
- activeTab medium Scoped page access on user gesture; moderate for wallet use.
- notifications low System notifications; expected for transaction alerts.
- offscreen low Off-screen document support; used for crypto operations.
- contextMenus low Adds right-click menu items; minimal risk.
- <all_urls> (host_permission) high Content scripts injected on every site; broad surface for a wallet, but partially justified.
Pillar Scores
Permissions5.50
Reputation3.00
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
19ba0d62a942…
Force block
— not fired
Score recovered
no
Elapsed
35.0s