Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tab to Window/Popup - Keyboard Shortcut

adbkphmimfcaeonicpmamfddbbnphikh
Risk Score
4.97
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 10,000
Rating 4.7
Last updated 2024-08-05 (24 months ago)
Manifest version MV3
CSP present ❌ no
Developer chrome@arthurcarabott.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • 8 moderate CVEs in bundled jquery@1.9.1 and jquery-ui@1.10.1 (XSS); no CSP amplifies risk (×1.5 CVE multiplier applied).
  • Privacy policy is Google's generic account policy — scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
  • No CSP on MV3 extension; dynamic script creation in vulnerable jquery version with no mitigation.
  • Extension stale 22 months; jquery/jquery-ui libs far behind fixed versions with no update.
  • install_url_hijack flag set; onInstalled opens external URL (target null but flag true).

Evidence

  • cve_moderate_x8 crx 8 moderate CVEs in jquery@1.9.1 and jquery-ui@1.10.1; all below fixed_in versions; no CSP → ×1.5 amplifier.
  • no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit hardening; amplifies CVE risk.
  • generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_extension store Last updated August 2024; 22 months since update; jquery libs severely outdated.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens external URL; target is null so destination unverified.
  • dynamic_script_creation crx script_src_dynamic found in jquery-1.9.1.min.js; combined with CVEs raises code quality risk.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reputation floor 2.0 applied; discounts capped per 0c (stale>18mo).
  • js_external_hosts crx Extension references acarabott.github.io and jqueryui.com as external JS hosts; 2 distinct domains.

CVE Exposures (8)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.10.1 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.10.1 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.10.1 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2016-7103 jquery-ui@1.10.1 moderate 1.12.0 jQuery-UI vulnerable to Cross-site Scripting in dialog closeText
CVE-2021-41183 jquery-ui@1.10.1 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Local preference storage; standard low-risk permission.
  • system.display low Read display geometry to place new windows; narrow, non-sensitive.
  • contextMenus low Adds right-click menu entry; no data access.

Pillar Scores

Permissions0.90
Reputation2.00
Network2.00
Webstore3.00
Maintenance6.00
Privacy10.00
Code Quality6.00
CVE Exposure7.50

Scoring History

fsssiedxa sssiedx 4.17 Medium review 2026-08-20
sssieddrubricxsx 4.49 Medium review 2026-08-20
v3.6 4.97 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA e13cbd46dd6e…
Force block — not fired
Score recovered no
Elapsed 34.2s