WeTab 新标签页
aikflfpejipbpjdlfabpgclhblkpaafo
Risk Score
6.70
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 + high CVE-2026-27601 in bundled underscore@1.8.3 (unfixed); no CSP amplifies XSS risk.
- No CSP + dynamic script injection (script_src_dynamic) + new Function() across 8+ files enables remote code execution.
- Privacy policy is Google's generic policy — does not scope to this extension; admits data collection and 3rd-party sharing.
- Newtab override + <all_urls> + scripting + free-webmail dev (no dev name, no verified publisher) = high-reach unaccountable actor.
- 12 external JS hosts including weatheroffer.com, test690.com subdomain, huggingface.co — diverse geo (CN/US/CA) with no CSP guard.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); fixed_in 1.13.8, not updated.
- no_csp_with_dynamic_script_and_cve crx csp_present=false + script_src_dynamic in 3 files + dom_sink_innerhtml in 6 files amplifies CVE XSS surface.
- privacy_policy_generic_google store Privacy URL points to myaccount.google.com/privacypolicy — generic Google policy, scope_extension=false, data_collection=true, 3rd-party sharing=true.
- newtab_override_broad_host manifest chrome_url_overrides.newtab + <all_urls> host permission + scripting = full page control on every new tab and all sites.
- free_webmail_no_dev_name store developer_email=infinitynewtab@gmail.com, developer_name empty, no verified publisher, no featured badge.
- external_host_diversity crx 12 external JS hosts across CN/US/CA including weatheroffer.com and api-hitab-com.test690.com (suspicious subdomain).
- function_constructor_widespread crx new Function() constructor found in 8 distinct files including Vue template compiler path (assets/js/9a231bfc.js).
- newtab_monetization_pattern store NewTab category with 200K installs, gmail dev, no privacy policy scoping, 12 external hosts — monetization shell fingerprint.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- unlimitedStorage low Allows large local storage; minor risk.
- sidePanel low UI panel access, low direct risk.
- contextMenus low Adds right-click menu items, low risk.
- activeTab low Scoped to user-initiated interaction only.
- storage low Standard local data storage, low risk.
- scripting high Allows programmatic script injection into pages; combined with <all_urls> is high risk.
- search medium Can manipulate browser search behavior.
- <all_urls> (host_permission) high Broad host access paired with scripting grants read/write on all sites.
- newtab override (chrome_url_overrides) medium Replaces every new tab — high reach for monetization or data collection.
Pillar Scores
Permissions7.00
Reputation7.50
Network4.50
Webstore7.00
Maintenance1.50
Privacy10.00
Code Quality8.00
CVE Exposure7.00
Scoring History
| sssiedn4afc0c87dp727562726963xsx | 6.79 | High | block | 2026-09-06 |
| v3.6 | 6.70 | High | block | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:00
Listing SHA
33ce5d39151e…
Force block
— not fired
Score recovered
no
Elapsed
—