Chestr - Universal Shopping Wishlist
aknpjjjjbhhpbdeboefcnnbafldhckej
Risk Score
6.61
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE (CVE-2021-23358) in bundled underscore@1.8.3 enables arbitrary code execution; unfixed for 31+ months.
- Privacy policy is Google's own account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Extension not updated in 31 months while critical/high CVEs remain unpatched.
- Broad host access (http+https://*/*) with scripting permission allows full page read/write on every site visited.
- Install URL hijack detected; uninstall URL redirects to getchestr.com — monetization/tracking surface.
Evidence
- critical_cve_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Still at vulnerable version.
- high_cve_underscore crx underscore@1.8.3 bundles CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
- privacy_policy_generic_google store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_31mo_with_cves store Last updated Nov 2023 (31 months); critical CVEs unpatched; triple-stale fingerprint.
- install_uninstall_url_hijack crx install_url_hijack=true; uninstall redirects to https://www.getchestr.com/uninstall.
- broad_host_permissions manifest host_permissions=[https://*/*, http://*/*] + content_scripts on all URLs + scripting = full-page capability.
- dom_xss_sink crx innerHTML assigned from variable in popup/index.js with no CSP; DOM-XSS risk amplified by no CSP + CVEs.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 2,000 installs with high-tier permissions and no developer name.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- scripting medium Allows injecting JS into pages; broad when paired with https://*/*.
- activeTab low Access limited to current tab on user gesture.
- https://*/* high Broad host access to all HTTPS sites; combined with scripting = full page read/write.
- http://*/* high Broad host access to all HTTP sites; same concern as HTTPS host permission.
Pillar Scores
Permissions4.50
Reputation3.50
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure7.00
Scoring History
| v3.6 | 6.61 | High | block | 2026-06-16 |
| v3.4-rev | 4.14 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
4d38774109cb…
Force block
— not fired
Score recovered
no
Elapsed
27.2s