Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Chestr - Universal Shopping Wishlist

aknpjjjjbhhpbdeboefcnnbafldhckej
Risk Score
6.61
Risk Level: High
Recommendation: 🚫 BLOCK
Category Shopping
Installs 2,000
Rating 3.9
Last updated 2023-11-09 (31 months ago)
Manifest version MV3
CSP present ❌ no
Developer besart@chestr.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE (CVE-2021-23358) in bundled underscore@1.8.3 enables arbitrary code execution; unfixed for 31+ months.
  • Privacy policy is Google's own account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Extension not updated in 31 months while critical/high CVEs remain unpatched.
  • Broad host access (http+https://*/*) with scripting permission allows full page read/write on every site visited.
  • Install URL hijack detected; uninstall URL redirects to getchestr.com — monetization/tracking surface.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Still at vulnerable version.
  • high_cve_underscore crx underscore@1.8.3 bundles CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
  • privacy_policy_generic_google store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_31mo_with_cves store Last updated Nov 2023 (31 months); critical CVEs unpatched; triple-stale fingerprint.
  • install_uninstall_url_hijack crx install_url_hijack=true; uninstall redirects to https://www.getchestr.com/uninstall.
  • broad_host_permissions manifest host_permissions=[https://*/*, http://*/*] + content_scripts on all URLs + scripting = full-page capability.
  • dom_xss_sink crx innerHTML assigned from variable in popup/index.js with no CSP; DOM-XSS risk amplified by no CSP + CVEs.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 2,000 installs with high-tier permissions and no developer name.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • scripting medium Allows injecting JS into pages; broad when paired with https://*/*.
  • activeTab low Access limited to current tab on user gesture.
  • https://*/* high Broad host access to all HTTPS sites; combined with scripting = full page read/write.
  • http://*/* high Broad host access to all HTTP sites; same concern as HTTPS host permission.

Pillar Scores

Permissions4.50
Reputation3.50
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure7.00

Scoring History

v3.6 6.61 High block 2026-06-16
v3.4-rev 4.14 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA 4d38774109cb…
Force block — not fired
Score recovered no
Elapsed 27.2s