Denji Chainsaw Man New Tab Extension
aphghkpebkfklfjjdolmfecaleiopife
Risk Score
6.22
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing (Privacy pillar: 10.0).
- NewTab override + uninstall URL hijack to gameograf.com = classic fan-theme monetization shell pattern.
- 9 moderate CVEs across jquery@1.9.1, jquery@3.4.1, and jquery-ui@1.12.1 — all below fixed_in versions; no CSP amplifies XSS risk.
- Uninstall URL redirects to gameograf.com UTM-tracked endpoint; dev email cluster has 15 siblings by dev_email and 10 by uninstall_url.
- No CSP present (MV3 default strictness does not cover bundled libs); 16 months stale with multiple vulnerable DOM-manipulation libs.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to index.html — replaces every new tab page.
- uninstall_url_hijack crx setUninstallURL points to gameograf.com with UTM tracking params.
- generic_privacy_policy store Privacy policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- cve_moderate_bulk crx 9 moderate CVEs in bundled jquery@1.9.1, jquery@3.4.1, jquery-ui@1.12.1; none at fixed_in version.
- no_csp manifest content_security_policy is null; no CSP amplifies XSS risk from vulnerable jQuery versions.
- operator_cluster_siblings api dev_email dimension shows 15 sibling extensions under info@gameograf.com; uninstall_url dimension shows 10.
- stale_extension store Last updated May 2025 but months_since_update=16; CVE-laden libs unpatched across that period.
- fan_theme_shell store Anime-character NewTab with no functional utility beyond wallpaper; matches fan-content/theme shell pattern.
CVE Exposures (9)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.12.1 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2021-41183 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- search medium Allows querying browser search API; relevant to NewTab/search override context.
- topSites medium Reads user's most visited sites; privacy-relevant browsing data.
- unlimitedStorage low Allows storing large amounts of local data; low standalone risk.
- storage low Standard local/sync storage; low risk.
- chrome_url_overrides.newtab high Replaces every new tab; high-reach entry point for ad/affiliate monetization.
Pillar Scores
Permissions3.50
Reputation5.00
Network3.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure5.25
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 03:20
Listing SHA
9563ef428de9…
Force block
— not fired
Score recovered
no
Elapsed
—