Keeper® Password Manager & Digital Vault
bfogiafebfohielmmehodmfbbebbbpei
Risk Score
5.14
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 (Arbitrary Code Execution) in bundled underscore@1.8.3; not patched to fixed_in 1.12.1.
- High CVE-2026-27601 in same underscore lib; two unfixed CVEs in DOM-manipulation lib triggers CVE ×1.5 amplifier.
- Broad host access (<all_urls>) combined with scripting, webRequest, browsingData, and privacy permissions — maximum capability surface.
- Privacy policy fetched but scope_extension==false and third_party_sharing==true without extension-specific scope — scores 10.0.
- Multiple eval() and new Function() calls in content scripts injected on all URLs elevate DOM-XSS and code-execution risk.
Evidence
- cve_critical_underscore crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical); fixed in 1.12.1. Currently unpatched.
- cve_high_underscore crx underscore@1.8.3 has CVE-2026-27601 (DoS, high); fixed in 1.13.8. Currently unpatched.
- broad_host_permissions manifest host_permissions include http://*/* https://*/* and <all_urls> paired with scripting and webRequest.
- eval_in_content_scripts crx eval() calls in libphonenumber.js and prompt/vendor.js content scripts injected on all pages.
- privacy_policy_not_extension_scoped api Policy fetched but scope_extension=false, third_party_sharing=true; no extension-specific data handling disclosed.
- csp_connect_src_broad manifest CSP connect-src includes wildcard '*' and 'data:' — allows arbitrary outbound connections from extension pages.
- no_developer_name store developer_name is empty string; identity relies solely on email and domain.
- cve_amplifier_applied crx CSP present but high/critical CVEs in underscore (DOM-manipulation lib) trigger ×1.5 CVE amplifier per rubric.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- contextMenus low UI affordance only; low standalone risk.
- tabs medium Can read tab URLs; needed for autofill targeting.
- alarms low Scheduling only; no data access.
- idle low Detects idle state; low risk.
- storage low Local extension storage; expected for password manager.
- browsingData high Can clear cookies/cache/history — broad destructive capability.
- webNavigation medium Monitors navigation events; needed for autofill triggers.
- scripting high Can inject scripts into any page via host_permissions <all_urls>.
- declarativeNetRequestWithHostAccess high Network request modification with host access; high capability.
- clipboardWrite medium Can write to clipboard; expected for password copy feature.
- offscreen low Off-screen document; limited risk in isolation.
- webRequest high Can observe all HTTP requests across <all_urls>.
- webRequestAuthProvider high Can intercept and supply HTTP auth credentials.
- privacy high Can modify browser privacy settings (WebRTC, referrer, etc.).
- http://*/* high Broad host access to all HTTP sites.
- https://*/* high Broad host access to all HTTPS sites.
- <all_urls> high Redundant broad host; combined with scripting is maximum reach.
Pillar Scores
Permissions6.50
Reputation3.50
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00
Scoring History
| v3.6 | 5.14 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.68 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA
66f381e39b56…
Force block
— not fired
Score recovered
no
Elapsed
37.6s