Loid Forger | Spy x Family New Tab Extension
biakkmbaipnmkmoeeffghfnjephhnjeb
Risk Score
6.37
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Uninstall URL hijack redirects to haberikra.com — classic monetization shell behavior.
- Privacy policy is Google's own policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- jquery@1.9.1 carries 3 medium CVEs (XSS); no CSP present, amplifying exploit surface.
- NewTab override with 29-month-stale extension — MV3 but CVEs + stale = triple-stale fingerprint.
- New-tab override with uninstall-URL hijack pattern matches traffic-monetization shell cluster.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL targets https://haberikra.com/ — 3rd-party redirect on uninstall.
- privacy_policy_generic store Policy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- cve_jquery_medium_x3 crx jquery@1.9.1 bundled; CVE-2015-9251, CVE-2019-11358, CVE-2020-11023; fixed_in 3.5.0.
- no_csp crx content_security_policy is null; jquery CVEs + no CSP raises XSS exploitation risk.
- newtab_override manifest chrome_url_overrides.newtab=index.html replaces every new tab page for all users.
- stale_maintenance store Last updated March 2024, 29 months ago; CVEs unpatched over that period.
- install_url_hijack crx onInstalled opens index.html (internal); low severity but confirms hijack pattern present.
- js_external_hosts_broad crx 12 external JS hosts including haberikra.com, pinterest.com, facebook.com, twitter.com.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- topSites medium Reads user's most visited sites; moderate privacy exposure for a NewTab page.
- unlimitedStorage low Allows unlimited local storage; low direct harm but enables large data caching.
- storage low Standard local storage API; low risk on its own.
- chrome_url_overrides.newtab medium Replaces every new tab; high-reach surface for ad injection or redirect monetization.
Pillar Scores
Permissions3.30
Reputation5.50
Network2.50
Webstore8.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 14:08
Listing SHA
a10bd44cf3f4…
Force block
— not fired
Score recovered
no
Elapsed
—