Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Keeper® Password Manager & Digital Vault

bfogiafebfohielmmehodmfbbebbbpei
Risk Score
5.14
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 2,000,000
Rating 4.8
Last updated 2026-06-13
Manifest version MV3
CSP present ✅ yes
Developer support@keepersecurity.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (Arbitrary Code Execution) in bundled underscore@1.8.3; not patched to fixed_in 1.12.1.
  • High CVE-2026-27601 in same underscore lib; two unfixed CVEs in DOM-manipulation lib triggers CVE ×1.5 amplifier.
  • Broad host access (<all_urls>) combined with scripting, webRequest, browsingData, and privacy permissions — maximum capability surface.
  • Privacy policy fetched but scope_extension==false and third_party_sharing==true without extension-specific scope — scores 10.0.
  • Multiple eval() and new Function() calls in content scripts injected on all URLs elevate DOM-XSS and code-execution risk.

Evidence

  • cve_critical_underscore crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical); fixed in 1.12.1. Currently unpatched.
  • cve_high_underscore crx underscore@1.8.3 has CVE-2026-27601 (DoS, high); fixed in 1.13.8. Currently unpatched.
  • broad_host_permissions manifest host_permissions include http://*/* https://*/* and <all_urls> paired with scripting and webRequest.
  • eval_in_content_scripts crx eval() calls in libphonenumber.js and prompt/vendor.js content scripts injected on all pages.
  • privacy_policy_not_extension_scoped api Policy fetched but scope_extension=false, third_party_sharing=true; no extension-specific data handling disclosed.
  • csp_connect_src_broad manifest CSP connect-src includes wildcard '*' and 'data:' — allows arbitrary outbound connections from extension pages.
  • no_developer_name store developer_name is empty string; identity relies solely on email and domain.
  • cve_amplifier_applied crx CSP present but high/critical CVEs in underscore (DOM-manipulation lib) trigger ×1.5 CVE amplifier per rubric.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • contextMenus low UI affordance only; low standalone risk.
  • tabs medium Can read tab URLs; needed for autofill targeting.
  • alarms low Scheduling only; no data access.
  • idle low Detects idle state; low risk.
  • storage low Local extension storage; expected for password manager.
  • browsingData high Can clear cookies/cache/history — broad destructive capability.
  • webNavigation medium Monitors navigation events; needed for autofill triggers.
  • scripting high Can inject scripts into any page via host_permissions <all_urls>.
  • declarativeNetRequestWithHostAccess high Network request modification with host access; high capability.
  • clipboardWrite medium Can write to clipboard; expected for password copy feature.
  • offscreen low Off-screen document; limited risk in isolation.
  • webRequest high Can observe all HTTP requests across <all_urls>.
  • webRequestAuthProvider high Can intercept and supply HTTP auth credentials.
  • privacy high Can modify browser privacy settings (WebRTC, referrer, etc.).
  • http://*/* high Broad host access to all HTTP sites.
  • https://*/* high Broad host access to all HTTPS sites.
  • <all_urls> high Redundant broad host; combined with scripting is maximum reach.

Pillar Scores

Permissions6.50
Reputation3.50
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00

Scoring History

v3.6 5.14 Medium review 2026-06-16
v3.4-rev 4.68 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA 66f381e39b56…
Force block — not fired
Score recovered no
Elapsed 37.6s