GTab New Tab (with ChatGPT & Claude 4.0)
ambcheakfbokmebglefpbbphbccekhhl
Risk Score
7.18
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Brand impersonation: claims ChatGPT & Claude 4.0 affiliation; dev is gmail, not verified owner of either brand.
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358 Arbitrary Code Execution); not patched.
- Dynamic script injection (script_src_dynamic) in multiple bundles enables runtime code loading from external hosts.
- New-tab override + <all_urls> + scripting = full control of browser start page and all web content.
- Privacy policy not scoped to this extension; data_collection and retention not disclosed; third_party_sharing silent.
Evidence
- brand_impersonation store Title claims 'ChatGPT & Claude 4.0'; confirmed_owner==false; developer is gtabteam@gmail.com with no brand affiliation.
- critical_cve crx underscore@1.8.3 bundled; CVE-2021-23358 critical ACE; fixed_in 1.12.1 — extension ships unfixed version.
- high_cve crx CVE-2026-27601 high-severity DoS in underscore@1.8.3; fixed_in 1.13.8.
- script_src_dynamic crx Dynamic <script src> creation found in action, member, sidepanel, popup bundles — runtime remote code loading.
- function_constructor crx new Function() used across 10+ files including Vue template compiler path.
- newtab_override_plus_all_urls manifest chrome_url_overrides.newtab + host_permissions <all_urls> + scripting = full browser start page + all-sites script injection.
- privacy_policy_inadequate api Policy fetched but scope_extension==false, data_collection==false, retention==false, third_party_silence==true.
- free_webmail_no_devname store developer_name empty; email gtabteam@gmail.com free webmail; no verified publisher badge.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab low Grants access only to currently active tab; low standalone risk.
- storage low Local data persistence; standard.
- unlimitedStorage low Expanded storage quota; low direct risk.
- sidePanel low Side panel UI; low risk.
- contextMenus low Adds right-click items; low risk.
- scripting high Can inject scripts into pages; paired with <all_urls> this is high risk.
- search medium Can override or query browser search; moderate risk.
- <all_urls> high Broad host access across all sites; combined with scripting enables full page access.
- newtab override medium chrome_url_overrides.newtab replaces new tab page; monetization/hijack vector.
Pillar Scores
Permissions7.00
Reputation8.00
Network4.50
Webstore8.50
Maintenance3.50
Privacy9.00
Code Quality8.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:02
Listing SHA
ab0a5d238c08…
Force block
— not fired
Score recovered
no
Elapsed
—