Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dex - Personal CRM & Contacts

amlpnkfionniifnajgcalfndolieichk
Risk Score
4.82
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 10,000
Rating 4.8
Last updated 2026-08-26
Manifest version MV3
CSP present ❌ no
Developer contact@getdex.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 allows arbitrary code execution; no CSP amplifies risk.
  • cookies + scripting across Gmail, Outlook 365, LinkedIn, Facebook — broad session and email content exposure.
  • Privacy policy fetched and admits data collection + third-party sharing but not scoped to this extension.
  • new Function() constructor in pageWorld.js combined with no CSP enables dynamic code execution.
  • No developer name listed; uninstall URL hijack flag set — governance gap for a high-capability extension.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); fixed_in 1.13.8.
  • no_csp_with_high_cve manifest content_security_policy is null (MV3 strict default absent); critical CVE in DOM-manipulation lib triggers CVE amplifier.
  • cookies_plus_broad_email_hosts manifest cookies permission paired with scripting on Gmail, Outlook365, LinkedIn, Facebook — session hijack surface.
  • function_constructor_pagworld crx new Function() in pageWorld.js — dynamic code construction without CSP guard.
  • privacy_policy_not_extension_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5-D fires +10.
  • no_developer_name store developer_name is empty; reduces accountability for a high-capability CRM extension.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target null but flag present — webstore penalty applies.
  • install_count_10k store 10,000 installs across high-value webmail + social hosts increases blast radius.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • *://*.getdex.com/* low Dev's own domain; expected for sync.
  • storage low Stores local CRM data; expected for this category.
  • tabs medium Can read tab URLs and titles across active browsing.
  • cookies high Can read/write cookies on all declared host origins including Gmail, LinkedIn, Facebook.
  • scripting high Can inject JS into all declared hosts; combined with broad host access elevates risk.
  • *://*.linkedin.com/* high Full cookie + script access to LinkedIn; professional contact data at risk.
  • *://*.facebook.com/* high Full cookie + script access to Facebook; social identity data at risk.
  • *://*.instagram.com/* high Full access to Instagram sessions.
  • *://*.mail.google.com/* high Script injection into Gmail; email content accessible.
  • *://calendar.google.com/* high Script access to Google Calendar; meeting/contact data exposed.
  • *://*.outlook.com/* high Script + cookie access to Outlook webmail.
  • *://*.office.com/* high Broad access to Microsoft 365 suite.
  • *://outlook.office365.com/* high Enterprise Outlook access; sensitive corporate email in scope.
  • *://outlook.cloud.microsoft/* high Microsoft cloud email/contacts access.
  • *://*.x.com/* medium Script access to X/Twitter sessions.
  • *://*.superhuman.com/* medium Script access to Superhuman email client.
  • *://*.live.com/* medium Microsoft Live identity/auth pages in scope.

Pillar Scores

Permissions6.50
Reputation6.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:26
Listing SHA 47927cfa44e1…
Force block — not fired
Score recovered no
Elapsed