Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Rabby Wallet

acmacodkjbdgmoleebolmdjonilkdbch
Risk Score
4.98
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 800,000
Rating 4.0
Last updated 2026-06-12
Manifest version MV3
CSP present ✅ yes
Developer hi@rabby.io
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: arbitrary code execution); version unpatched.
  • Privacy policy on debank.com does not scope to this extension and admits data collection without retention disclosure.
  • Uninstall URL hijack detected; destination not captured but flag is authoritative.
  • Multiple new Function() constructors in background.js and offscreen.js alongside <all_urls> host access.
  • react@16.13.1 (below 16.4 threshold) bundled with underscore CVEs and CSP present but DOM-XSS sink in content-script.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed_in 1.12.1. Library not updated.
  • high_cve_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8.
  • privacy_policy_inadequate store Policy at debank.com: fetched=true, scope_extension=false, data_collection=true, retention=false, third_party_silence=true.
  • uninstall_url_hijack crx uninstall_url_hijack=true; chrome.runtime.setUninstallURL() points to third-party destination.
  • function_constructor_multi crx new Function() in background.js, offscreen.js, and two Trezor vendor files. Dynamic code execution surface.
  • dom_xss_sink crx innerHTML on user-controlled variable in content-script.js injected on all URLs.
  • host_permission_all_urls manifest <all_urls> host permission with broad content_scripts_matches including http://*/* and https://*/*.
  • verified_publisher_no_developer_name store verified_publisher=true but developer_name is empty string; email hi@rabby.io on rabby.io domain resolves.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • scripting medium Can inject JS into pages; paired with <all_urls> host permission raises risk.
  • storage low Standard key-value storage; expected for a wallet.
  • unlimitedStorage low Removes storage quota; minor risk for wallet caching.
  • alarms low Periodic background tasks; low standalone risk.
  • activeTab medium Scoped page access on user gesture; moderate for wallet use.
  • notifications low System notifications; expected for transaction alerts.
  • offscreen low Off-screen document support; used for crypto operations.
  • contextMenus low Adds right-click menu items; minimal risk.
  • <all_urls> (host_permission) high Content scripts injected on every site; broad surface for a wallet, but partially justified.

Pillar Scores

Permissions5.50
Reputation3.00
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA 19ba0d62a942…
Force block — not fired
Score recovered no
Elapsed 35.0s