Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YouTube AI Chapters

bpeipmghmalpblacdelkhbnjkfnlhkhe
Risk Score
6.14
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category AI
Installs 4
Rating
Last updated 2024-12-03 (21 months ago)
Manifest version MV3
CSP present ✅ yes
Developer sanchit.sharma98@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (Arbitrary Code Execution); version unfixed.
  • Privacy policy is Google's generic account policy — does not scope to this extension at all (+10.0).
  • Brand impersonation: uses 'openai' and 'youtube' brands without verified ownership; free-webmail dev with no developer name.
  • High-impact permissions (webRequest + declarativeNetRequestWithHostAccess) on a 3-install, unverified extension.
  • 20-month stale extension with CVEs and no updates; tail-attack surface (tiny install base, high permissions).

Evidence

  • critical_cve crx underscore@1.8.3 has CVE-2021-23358 (critical, Arbitrary Code Execution); fixed_in 1.12.1 — unfixed.
  • high_cve crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via unlimited recursion); fixed_in 1.13.8 — unfixed.
  • privacy_policy_generic store Privacy policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • brand_impersonation store brand_mention.is_impersonation=true for openai+youtube; dev is free-webmail gmail, confirmed_owner=false.
  • free_webmail_no_dev_name store developer_email=sanchit.sharma98@gmail.com, developer_name empty, no verified publisher badge.
  • install_perm_anomaly store Only 3 installs with HIGH-tier permissions (webRequest, declarativeNetRequestWithHostAccess); tail attack surface.
  • maintenance_stale store 20 months since last update; CVEs present and unfixed, no changelog.
  • function_constructor_node_modules crx 15 function_constructor signals found; all in node_modules dev-tool paths (tapable, webpack, ajv), not runtime code.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Stores local settings; limited blast radius.
  • webRequest high Can observe all network requests; broad interception capability.
  • declarativeNetRequest medium Allows rule-based request blocking/redirecting.
  • declarativeNetRequestWithHostAccess high Extends declarativeNetRequest with host-level modification power.
  • https://*.openai.com/ medium Host permission scoped to OpenAI API; plausible for stated function.
  • https://www.youtube-nocookie.com/embed/* medium Content script on YouTube embed pages; reads page content.
  • https://www.youtube.com/* medium Content script on YouTube; can read video data and DOM.

Pillar Scores

Permissions5.50
Reputation8.00
Network2.00
Webstore6.00
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure7.00

Scoring History

sssiedn16ae04cadp727562726963xsx 6.32 High block 2026-09-09
v3.6 6.14 High review 2026-08-31

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:37
Listing SHA d2d3c88c3f5d…
Force block — not fired
Score recovered no
Elapsed