Norton Password Manager
admmjipmmciaobhojoghlmleefbicajg
Risk Score
4.31
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy (gendigital.com/privacy) is not scoped to this extension and data_collection=false — opaque data handling for a 5M-user credential manager.
- No CSP present on MV3 extension with <all_urls> + scripting + webRequest; function_constructor calls and innerHTML sink amplify XSS risk.
- React 16.13.1 bundled; below XSS-fix threshold (16.4) with no CSP — DOM-XSS sink in vendor/libs.react.js is higher risk.
- Low rating (2.7) across a large install base; no developer display name despite corporate email, reducing accountability signals.
- Content scripts injected on <all_urls> including financial checkout pages (Amazon, Citi, Zappos) — broad credential/payment page access.
Evidence
- no_csp_mv3 manifest content_security_policy is null; MV3 default is stricter but absence of explicit CSP leaves eval-like constructs less constrained.
- privacy_policy_not_extension_scoped api gendigital.com/privacy: fetched=true, scope_extension=false, data_collection=false — generic corporate policy, not scoped to this extension.
- function_constructor_multiple_files crx new Function() constructor found in 6 content-script files; pattern is boilerplate globalThis polyfill but still present.
- dom_sink_innerhtml_no_csp crx innerHTML sink in vendor/libs.react.js (React 16.13.1 < 16.4); no CSP to mitigate DOM-XSS.
- verified_publisher_nortonlifelock store verified_publisher=true, developer_domain nortonlifelock.com resolves; recognized security brand.
- broad_host_permissions_password_manager manifest <all_urls> host permission + scripting + webRequest; justified for password manager but high capability surface.
- low_rating_large_install_base store Rating 2.7 on 5M installs; no review red flags in structured data but low score is notable.
- financial_checkout_content_scripts manifest Content scripts scoped to Amazon, Citi, Zappos, Steam checkout pages — direct access to payment flows.
Permissions Breakdown
- contextMenus low UI convenience; minimal data access.
- notifications low Display only; no data exfil risk.
- storage low Local extension state storage.
- tabs medium Can read tab URLs and titles across all sites.
- webNavigation medium Observe navigation events; tracks browsing patterns.
- webRequest high Observe all HTTP traffic on all URLs; paired with <all_urls>.
- alarms low Background scheduling only.
- clipboardWrite medium Can write to clipboard; password manager use case but sensitive.
- scripting high Inject scripts into any page; paired with <all_urls> broad reach.
- <all_urls> (host_permission) high Full access to all websites; required for password manager function.
Pillar Scores
Permissions5.00
Reputation3.50
Network3.50
Webstore2.50
Maintenance0.00
Privacy9.00
Code Quality3.50
CVE Exposure0.00
Scoring History
| xx pfsssiedxasssiedx | 4.14 | Medium | review | 2026-08-20 |
| "fsssiedxa$'sssiedx | 2.77 | Low | review | 2026-08-20 |
| %27fsssiedxa$"sssiedx | 4.09 | Medium | review | 2026-08-20 |
| $'fsssiedxa"sssiedx | 4.41 | Medium | review | 2026-08-20 |
| fsssiedxa$'sssiedx | 2.99 | Low | review | 2026-08-20 |
| <fsssiedxa'sssiedx | 3.59 | Low | review | 2026-08-17 |
| <fsssiedxa$"sssiedx | 4.02 | Medium | review | 2026-08-17 |
| xx pfsssiedxa$"sssiedx | 2.81 | Low | review | 2026-08-17 |
| 'fsssiedxa sssiedx | 3.44 | Low | review | 2026-08-17 |
| fsssiedxa$"sssiedx | 4.21 | Medium | review | 2026-08-17 |
| <fsssiedxa'sssiedx | 2.68 | Low | review | 2026-08-17 |
| fsssiedxa<sssiedx | 2.77 | Low | review | 2026-08-17 |
| sssieddrubricxsx | 3.33 | Low | review | 2026-08-15 |
| v3.6</script><script>uS2d(9531)</script> | 2.63 | Low | review | 2026-08-05 |
| dfb__${98991*97996}__::.x | 2.86 | Low | review | 2026-08-05 |
| dfb{{98991*97996}}xca | 2.68 | Low | review | 2026-08-05 |
| v3.6&n942055=v906326 | 4.02 | Medium | review | 2026-08-05 |
| dfb[[${98991*97996}]]xca | 2.95 | Low | review | 2026-08-04 |
| v3.6&n969085=v975725 | 2.75 | Low | review | 2026-08-04 |
| v3.69415324 | 3.37 | Low | review | 2026-07-29 |
| v3.69211"();}]9096 | 3.57 | Low | review | 2026-07-29 |
| v3.6"onmouseover=DgUZ(96622)" | 2.90 | Low | review | 2026-07-29 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 2.86 | Low | review | 2026-07-29 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 3.72 | Low | review | 2026-07-29 |
| bfgx8989%C0%BEz1%C0%BCz2a%90bcxhjl8989 | 3.37 | Low | review | 2026-07-29 |
| v3.6'"()&%<zzz><ScRiPt >DgUZ(9473)</ScRiPt> | 2.81 | Low | review | 2026-07-29 |
| v3.6&n917899=v948084 | 2.86 | Low | review | 2026-07-29 |
| v3.6 | 4.31 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA
9fc52d90ae72…
Force block
— not fired
Score recovered
no
Elapsed
49.5s