Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

bhdkkcffcbililblmbhhgbalkilpgjnn

bhdkkcffcbililblmbhhgbalkilpgjnn
Risk Score
4.64
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Content script on web.whatsapp.com gives full read/write access to WhatsApp messages and session data.
  • Uninstall and install URL hijacks both flagged — likely opens third-party pages on install/uninstall.
  • Privacy policy is Google's generic account policy, not scoped to this extension; data practices undisclosed.
  • No developer identity (no name, no email, no title) — unaccountable publisher.
  • No CSP declared (MV3 default applies) combined with innerHTML DOM-XSS sink in bundled library.

Evidence

  • content_script_whatsapp manifest content_scripts_matches includes https://web.whatsapp.com/* — full DOM access to WhatsApp Web sessions.
  • uninstall_install_url_hijack manifest Both uninstall_url_hijack and install_url_hijack are true; targets are null but flags are set.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true.
  • no_developer_identity store developer_name, developer_email, and title are all empty strings — publisher is unidentifiable.
  • dom_xss_sink crx assets/sweetAlert.js: innerHTML assigned from variable — DOM-XSS risk, no CSP to mitigate.
  • no_csp manifest content_security_policy is null; csp_present=false. MV3 default applies but no explicit hardening.
  • external_js_hosts crx 12 external JS hosts referenced including tinyurl.com and server.chatsac.com — broad outbound surface.
  • privacy_policy_third_party_sharing api Policy admits data_collection=true, third_party_sharing=true but is not scoped to this extension.

Permissions Breakdown

  • storage low Stores local extension data; low standalone risk.
  • tabs medium Can read tab URLs and metadata; moderate privacy risk.
  • content_scripts: https://painel.chatsac.com/* medium Injects scripts into chatsac panel; scoped to dev-controlled domain.
  • content_scripts: https://web.whatsapp.com/* high Full script access to WhatsApp Web — can read messages, contacts, sessions.

Pillar Scores

Permissions2.30
Reputation7.50
Network0.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:51
Listing SHA fb46dc82417d…
Force block — not fired
Score recovered no
Elapsed