Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Free VPN for Chrome - freemybrowser

bibmocmlcdhadgblaekimealfcnafgfn
Risk Score
5.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 20,000
Rating 3.9
Last updated 2025-05-12 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@freemybrowser.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case privacy score.
  • proxy + cookies + https://*/* combo: extension can intercept and read all HTTPS cookies across every site visited.
  • No developer name listed; missing organizational accountability for a high-capability VPN extension.
  • Extension contacts facebook.com externally — unexpected third-party JS host for a VPN with broad cookie access.
  • 15 months since last update; stale for a security-critical extension handling all user traffic.

Evidence

  • privacy_policy_admits_data_and_sharing_not_scoped api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
  • proxy+cookies+broad_host manifest proxy, cookies, declarativeNetRequestWithHostAccess, webRequest all declared with https://*/* → high-capability cluster.
  • no_developer_name store developer_name is empty string; verified_publisher present but no named org; reputation +1.0.
  • facebook_external_host crx js_external_hosts includes facebook.com — unexpected for a VPN; potential tracking/analytics dependency.
  • install_url_hijack crx install_url_hijack=true targeting settings.html (internal); minor signal, no third-party redirect.
  • months_since_update_15 store 15 months since last update → maintenance +6.0 (6-12 bracket exceeded; 12-24 = +6.0).
  • dom_sink_innerhtml_userctrl crx popup.100f6462.js: innerHTML from variable; no CSP present → +2.0 code quality (FIX B applies: csp_present=false).
  • verified_publisher_featured store Both verified_publisher and is_featured_by_google true; reputation -3.0 -2.0; but CAPABILITY GATE applies (proxy/webRequest/cookies) → cap discount at -1.0 per 0c (monetization not present but stale >18mo? No, 15mo; cve empty, domain resolves → full discount applies minus gate).

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; standard for VPN routing decisions.
  • webRequest high Intercepts all network requests; core to VPN but high-impact capability.
  • proxy high Routes all browser traffic; highest-risk permission for a VPN extension.
  • unlimitedStorage low Local storage quota removal; low direct risk.
  • declarativeNetRequestWithHostAccess high Can block/redirect requests across all HTTPS hosts.
  • background low Persistent background processing; expected for VPN.
  • webNavigation medium Observes navigation events across all tabs.
  • cookies high Read/write cookies site-wide; paired with broad host access multiplies risk.
  • storage low Local extension storage; standard.
  • webRequestAuthProvider medium Can supply authentication credentials to network requests.
  • https://*/* high Broad host access over all HTTPS sites; amplifies cookies+proxy risk.

Pillar Scores

Permissions7.50
Reputation3.50
Network4.50
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:51
Listing SHA 23d1e39bf6ca…
Force block — not fired
Score recovered no
Elapsed