Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WeTab 新标签页

aikflfpejipbpjdlfabpgclhblkpaafo
Risk Score
6.70
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 200,000
Rating 4.0
Last updated 2026-03-12 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer infinitynewtab@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 + high CVE-2026-27601 in bundled underscore@1.8.3 (unfixed); no CSP amplifies XSS risk.
  • No CSP + dynamic script injection (script_src_dynamic) + new Function() across 8+ files enables remote code execution.
  • Privacy policy is Google's generic policy — does not scope to this extension; admits data collection and 3rd-party sharing.
  • Newtab override + <all_urls> + scripting + free-webmail dev (no dev name, no verified publisher) = high-reach unaccountable actor.
  • 12 external JS hosts including weatheroffer.com, test690.com subdomain, huggingface.co — diverse geo (CN/US/CA) with no CSP guard.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); fixed_in 1.13.8, not updated.
  • no_csp_with_dynamic_script_and_cve crx csp_present=false + script_src_dynamic in 3 files + dom_sink_innerhtml in 6 files amplifies CVE XSS surface.
  • privacy_policy_generic_google store Privacy URL points to myaccount.google.com/privacypolicy — generic Google policy, scope_extension=false, data_collection=true, 3rd-party sharing=true.
  • newtab_override_broad_host manifest chrome_url_overrides.newtab + <all_urls> host permission + scripting = full page control on every new tab and all sites.
  • free_webmail_no_dev_name store developer_email=infinitynewtab@gmail.com, developer_name empty, no verified publisher, no featured badge.
  • external_host_diversity crx 12 external JS hosts across CN/US/CA including weatheroffer.com and api-hitab-com.test690.com (suspicious subdomain).
  • function_constructor_widespread crx new Function() constructor found in 8 distinct files including Vue template compiler path (assets/js/9a231bfc.js).
  • newtab_monetization_pattern store NewTab category with 200K installs, gmail dev, no privacy policy scoping, 12 external hosts — monetization shell fingerprint.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • unlimitedStorage low Allows large local storage; minor risk.
  • sidePanel low UI panel access, low direct risk.
  • contextMenus low Adds right-click menu items, low risk.
  • activeTab low Scoped to user-initiated interaction only.
  • storage low Standard local data storage, low risk.
  • scripting high Allows programmatic script injection into pages; combined with <all_urls> is high risk.
  • search medium Can manipulate browser search behavior.
  • <all_urls> (host_permission) high Broad host access paired with scripting grants read/write on all sites.
  • newtab override (chrome_url_overrides) medium Replaces every new tab — high reach for monetization or data collection.

Pillar Scores

Permissions7.00
Reputation7.50
Network4.50
Webstore7.00
Maintenance1.50
Privacy10.00
Code Quality8.00
CVE Exposure7.00

Scoring History

sssiedn4afc0c87dp727562726963xsx 6.79 High block 2026-09-06
v3.6 6.70 High block 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:00
Listing SHA 33ce5d39151e…
Force block — not fired
Score recovered no
Elapsed