Re-newtab
ccfjmnfklnaofoggkolocloghafpoccc
Risk Score
7.05
Risk Level:
High
Recommendation:
🚫 BLOCK
FORCE-BLOCK
Top Risks
- FORCE BLOCK: management + new-tab/search override — extension can disable security tools AND has full traffic-routing capability.
- NewTab override with management+history+sessions gives persistent high-privilege access to all browsing activity
- Multiple medium CVEs in jquery@3.3.1 and jquery@1.9.1 with no CSP — XSS amplified by no content-security-policy (×1.5 CVE amplifier)
- eval_user_input in newtab.js + script_src_dynamic + innerHTML without CSP = serious code-execution/XSS surface
- Extension not updated in 25 months (stale MV3); vulnerabilities unlikely to be patched
Evidence
- newtab_override manifest chrome_url_overrides.newtab replaces every new tab — max passive reach.
- management_permission manifest 'management' permission allows enumeration/disabling of other extensions — elevated privilege.
- cve_jquery_no_csp crx jquery@3.3.1 and 1.9.1 both carry multiple moderate XSS CVEs; no CSP to mitigate — ×1.5 amplifier applied.
- eval_and_dynamic_script crx eval_user_input in newtab.js/calc.js and script_src_dynamic in newtab.js without CSP.
- stale_extension store Last updated May 2024, 25 months ago — no patch for known CVEs.
- free_webmail_dev store Developer email guokai.dev+newtab@gmail.com; no business name listed.
- privacy_third_party api Policy fetched, scoped, no data_collection claimed but third_party_sharing=true; retention not disclosed.
- 12_external_js_hosts crx 12 distinct external JS hosts including darksky.net, kiro.me, getbootstrap.com — >3 distinct registrable domains.
CVE Exposures (6)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- topSites medium Reads frequently visited sites — privacy exposure.
- management high Can enumerate/disable/uninstall other extensions — high privilege.
- sessions medium Access to recently closed tabs/windows across sessions.
- history high Full browsing history access — broad user-tracking surface.
- downloads medium Can list and interact with download history.
- downloads.open medium Can open downloaded files — minor escalation vector.
- tabs medium Access to URL/title of all open tabs.
- bookmarks medium Read/write access to all bookmarks.
- favicon low Access to site favicons; low standalone risk.
- storage low Local extension storage; standard.
- unlimitedStorage low Allows large local storage; low risk without exfil.
- search medium Can trigger browser search — potential query observation.
- identity medium Can request OAuth tokens; depends on scopes used.
- chrome_url_overrides.newtab high Replaces every new tab page — maximum passive reach for all browsing sessions.
Pillar Scores
Permissions7.50
Reputation3.50
Network3.50
Webstore5.50
Maintenance8.50
Privacy2.00
Code Quality7.50
CVE Exposure5.00
Scoring History
| v3.6 | 7.05 | High | block | 2026-06-16 |
| v3.4-rev | 5.42 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA
95ab31cde790…
Force block
🚫 fired
Score recovered
no
Elapsed
39.8s