Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Re-newtab

ccfjmnfklnaofoggkolocloghafpoccc
Risk Score
7.05
Risk Level: High
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category NewTab
Installs 3,000
Rating 4.8
Last updated 2024-05-06 (25 months ago)
Manifest version MV3
CSP present ❌ no
Developer guokai.dev+newtab@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + new-tab/search override — extension can disable security tools AND has full traffic-routing capability.
  • NewTab override with management+history+sessions gives persistent high-privilege access to all browsing activity
  • Multiple medium CVEs in jquery@3.3.1 and jquery@1.9.1 with no CSP — XSS amplified by no content-security-policy (×1.5 CVE amplifier)
  • eval_user_input in newtab.js + script_src_dynamic + innerHTML without CSP = serious code-execution/XSS surface
  • Extension not updated in 25 months (stale MV3); vulnerabilities unlikely to be patched

Evidence

  • newtab_override manifest chrome_url_overrides.newtab replaces every new tab — max passive reach.
  • management_permission manifest 'management' permission allows enumeration/disabling of other extensions — elevated privilege.
  • cve_jquery_no_csp crx jquery@3.3.1 and 1.9.1 both carry multiple moderate XSS CVEs; no CSP to mitigate — ×1.5 amplifier applied.
  • eval_and_dynamic_script crx eval_user_input in newtab.js/calc.js and script_src_dynamic in newtab.js without CSP.
  • stale_extension store Last updated May 2024, 25 months ago — no patch for known CVEs.
  • free_webmail_dev store Developer email guokai.dev+newtab@gmail.com; no business name listed.
  • privacy_third_party api Policy fetched, scoped, no data_collection claimed but third_party_sharing=true; retention not disclosed.
  • 12_external_js_hosts crx 12 distinct external JS hosts including darksky.net, kiro.me, getbootstrap.com — >3 distinct registrable domains.

CVE Exposures (6)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • topSites medium Reads frequently visited sites — privacy exposure.
  • management high Can enumerate/disable/uninstall other extensions — high privilege.
  • sessions medium Access to recently closed tabs/windows across sessions.
  • history high Full browsing history access — broad user-tracking surface.
  • downloads medium Can list and interact with download history.
  • downloads.open medium Can open downloaded files — minor escalation vector.
  • tabs medium Access to URL/title of all open tabs.
  • bookmarks medium Read/write access to all bookmarks.
  • favicon low Access to site favicons; low standalone risk.
  • storage low Local extension storage; standard.
  • unlimitedStorage low Allows large local storage; low risk without exfil.
  • search medium Can trigger browser search — potential query observation.
  • identity medium Can request OAuth tokens; depends on scopes used.
  • chrome_url_overrides.newtab high Replaces every new tab page — maximum passive reach for all browsing sessions.

Pillar Scores

Permissions7.50
Reputation3.50
Network3.50
Webstore5.50
Maintenance8.50
Privacy2.00
Code Quality7.50
CVE Exposure5.00

Scoring History

v3.6 7.05 High block 2026-06-16
v3.4-rev 5.42 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA 95ab31cde790…
Force block 🚫 fired
Score recovered no
Elapsed 39.8s