Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Loid Forger | Spy x Family New Tab Extension

biakkmbaipnmkmoeeffghfnjephhnjeb
Risk Score
6.37
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 181
Rating
Last updated 2024-03-28 (29 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack redirects to haberikra.com — classic monetization shell behavior.
  • Privacy policy is Google's own policy, not scoped to this extension; admits data collection and 3rd-party sharing.
  • jquery@1.9.1 carries 3 medium CVEs (XSS); no CSP present, amplifying exploit surface.
  • NewTab override with 29-month-stale extension — MV3 but CVEs + stale = triple-stale fingerprint.
  • New-tab override with uninstall-URL hijack pattern matches traffic-monetization shell cluster.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL targets https://haberikra.com/ — 3rd-party redirect on uninstall.
  • privacy_policy_generic store Policy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • cve_jquery_medium_x3 crx jquery@1.9.1 bundled; CVE-2015-9251, CVE-2019-11358, CVE-2020-11023; fixed_in 3.5.0.
  • no_csp crx content_security_policy is null; jquery CVEs + no CSP raises XSS exploitation risk.
  • newtab_override manifest chrome_url_overrides.newtab=index.html replaces every new tab page for all users.
  • stale_maintenance store Last updated March 2024, 29 months ago; CVEs unpatched over that period.
  • install_url_hijack crx onInstalled opens index.html (internal); low severity but confirms hijack pattern present.
  • js_external_hosts_broad crx 12 external JS hosts including haberikra.com, pinterest.com, facebook.com, twitter.com.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • topSites medium Reads user's most visited sites; moderate privacy exposure for a NewTab page.
  • unlimitedStorage low Allows unlimited local storage; low direct harm but enables large data caching.
  • storage low Standard local storage API; low risk on its own.
  • chrome_url_overrides.newtab medium Replaces every new tab; high-reach surface for ad injection or redirect monetization.

Pillar Scores

Permissions3.30
Reputation5.50
Network2.50
Webstore8.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 14:08
Listing SHA a10bd44cf3f4…
Force block — not fired
Score recovered no
Elapsed