Dex - Personal CRM & Contacts
amlpnkfionniifnajgcalfndolieichk
Risk Score
4.82
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 allows arbitrary code execution; no CSP amplifies risk.
- cookies + scripting across Gmail, Outlook 365, LinkedIn, Facebook — broad session and email content exposure.
- Privacy policy fetched and admits data collection + third-party sharing but not scoped to this extension.
- new Function() constructor in pageWorld.js combined with no CSP enables dynamic code execution.
- No developer name listed; uninstall URL hijack flag set — governance gap for a high-capability extension.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); fixed_in 1.13.8.
- no_csp_with_high_cve manifest content_security_policy is null (MV3 strict default absent); critical CVE in DOM-manipulation lib triggers CVE amplifier.
- cookies_plus_broad_email_hosts manifest cookies permission paired with scripting on Gmail, Outlook365, LinkedIn, Facebook — session hijack surface.
- function_constructor_pagworld crx new Function() in pageWorld.js — dynamic code construction without CSP guard.
- privacy_policy_not_extension_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5-D fires +10.
- no_developer_name store developer_name is empty; reduces accountability for a high-capability CRM extension.
- uninstall_url_hijack crx uninstall_url_hijack=true; target null but flag present — webstore penalty applies.
- install_count_10k store 10,000 installs across high-value webmail + social hosts increases blast radius.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- *://*.getdex.com/* low Dev's own domain; expected for sync.
- storage low Stores local CRM data; expected for this category.
- tabs medium Can read tab URLs and titles across active browsing.
- cookies high Can read/write cookies on all declared host origins including Gmail, LinkedIn, Facebook.
- scripting high Can inject JS into all declared hosts; combined with broad host access elevates risk.
- *://*.linkedin.com/* high Full cookie + script access to LinkedIn; professional contact data at risk.
- *://*.facebook.com/* high Full cookie + script access to Facebook; social identity data at risk.
- *://*.instagram.com/* high Full access to Instagram sessions.
- *://*.mail.google.com/* high Script injection into Gmail; email content accessible.
- *://calendar.google.com/* high Script access to Google Calendar; meeting/contact data exposed.
- *://*.outlook.com/* high Script + cookie access to Outlook webmail.
- *://*.office.com/* high Broad access to Microsoft 365 suite.
- *://outlook.office365.com/* high Enterprise Outlook access; sensitive corporate email in scope.
- *://outlook.cloud.microsoft/* high Microsoft cloud email/contacts access.
- *://*.x.com/* medium Script access to X/Twitter sessions.
- *://*.superhuman.com/* medium Script access to Superhuman email client.
- *://*.live.com/* medium Microsoft Live identity/auth pages in scope.
Pillar Scores
Permissions6.50
Reputation6.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:26
Listing SHA
47927cfa44e1…
Force block
— not fired
Score recovered
no
Elapsed
—