Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Naruto Anime 4K Ultra HD 15 Wallpaper

bmamihpoapicofildgmclopghjandfbj
Risk Score
6.11
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 76
Rating
Last updated 2026-05-13 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer eminearsiz0@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack redirects to gameograf.com ad-tech domain — clear monetization shell behavior.
  • Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
  • NewTab override with 'search' permission enables search-query interception and ad monetization on every new tab.
  • jQuery 1.9.1 bundled with 3 medium CVEs (XSS), version far below fixed_in 3.5.0; no CSP amplifies risk.
  • Free-webmail developer (gmail), no verified publisher, no business website — no accountability chain.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL to gameograf.com with UTM params — confirmed ad-tech monetization shell.
  • privacy_policy_generic store PP URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension at all.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; NewTab hijack with search+topSites is classic monetization vector.
  • cve_jquery_1.9.1 crx jquery@1.9.1 carries 3 medium XSS CVEs; no CSP present, amplifying DOM-manipulation risk (×1.5 multiplier).
  • free_webmail_developer store Developer email eminearsiz0@gmail.com; no business domain, no verified publisher badge.
  • install_url_hijack crx onInstalled opens index.html — install hijack noted; low severity but consistent with shell pattern.
  • 12_external_js_hosts crx 12 external JS hosts including gameograf.com, jqueryui.com, popper.js.org — broad external dependency surface.
  • no_csp manifest content_security_policy is null; MV3 has defaults but no explicit CSP with vulnerable jquery@1.9.1 is risky.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • search medium Can read and potentially redirect search queries; concerning for a NewTab override.
  • topSites medium Exposes user browsing history top sites; combined with NewTab monetization risk.
  • unlimitedStorage low Allows unbounded local storage; low standalone risk.
  • storage low Standard local storage access; low risk alone.
  • chrome_url_overrides.newtab medium Hijacks every new tab; prime real estate for ad-monetization shell patterns.

Pillar Scores

Permissions5.00
Reputation7.50
Network2.50
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 08:42
Listing SHA 2d108b107239…
Force block — not fired
Score recovered no
Elapsed