Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GTab New Tab (with ChatGPT & Claude 4.0)

ambcheakfbokmebglefpbbphbccekhhl
Risk Score
7.18
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 92
Rating
Last updated 2025-08-12 (12 months ago)
Manifest version MV3
CSP present ✅ yes
Developer gtabteam@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: claims ChatGPT & Claude 4.0 affiliation; dev is gmail, not verified owner of either brand.
  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358 Arbitrary Code Execution); not patched.
  • Dynamic script injection (script_src_dynamic) in multiple bundles enables runtime code loading from external hosts.
  • New-tab override + <all_urls> + scripting = full control of browser start page and all web content.
  • Privacy policy not scoped to this extension; data_collection and retention not disclosed; third_party_sharing silent.

Evidence

  • brand_impersonation store Title claims 'ChatGPT & Claude 4.0'; confirmed_owner==false; developer is gtabteam@gmail.com with no brand affiliation.
  • critical_cve crx underscore@1.8.3 bundled; CVE-2021-23358 critical ACE; fixed_in 1.12.1 — extension ships unfixed version.
  • high_cve crx CVE-2026-27601 high-severity DoS in underscore@1.8.3; fixed_in 1.13.8.
  • script_src_dynamic crx Dynamic <script src> creation found in action, member, sidepanel, popup bundles — runtime remote code loading.
  • function_constructor crx new Function() used across 10+ files including Vue template compiler path.
  • newtab_override_plus_all_urls manifest chrome_url_overrides.newtab + host_permissions <all_urls> + scripting = full browser start page + all-sites script injection.
  • privacy_policy_inadequate api Policy fetched but scope_extension==false, data_collection==false, retention==false, third_party_silence==true.
  • free_webmail_no_devname store developer_name empty; email gtabteam@gmail.com free webmail; no verified publisher badge.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • activeTab low Grants access only to currently active tab; low standalone risk.
  • storage low Local data persistence; standard.
  • unlimitedStorage low Expanded storage quota; low direct risk.
  • sidePanel low Side panel UI; low risk.
  • contextMenus low Adds right-click items; low risk.
  • scripting high Can inject scripts into pages; paired with <all_urls> this is high risk.
  • search medium Can override or query browser search; moderate risk.
  • <all_urls> high Broad host access across all sites; combined with scripting enables full page access.
  • newtab override medium chrome_url_overrides.newtab replaces new tab page; monetization/hijack vector.

Pillar Scores

Permissions7.00
Reputation8.00
Network4.50
Webstore8.50
Maintenance3.50
Privacy9.00
Code Quality8.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:02
Listing SHA ab0a5d238c08…
Force block — not fired
Score recovered no
Elapsed