Safe Surf
cgmllohkcppmnkfpijpngkplpdbikhlf
Risk Score
5.99
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy—not scoped to this extension; data_collection+third_party_sharing admitted without extension context (Privacy=10.0).
- nativeMessaging to unrecognized publisher: allows escape to host OS with no accountability.
- Broad host permissions (http://*/*, https://*/*) combined with webRequest and scripting grants full page read/write capability.
- Multiple innerHTML DOM-XSS sinks (no CSP) combined with function_constructor use across 5+ files without CSP protection.
- Uninstall URL hijack flag set; Sentry SDK prototype-pollution CVE at unknown version (cannot confirm fixed).
Evidence
- privacy_policy_google_generic store PP URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
- native_messaging_unrecognized manifest nativeMessaging declared; native_messaging_check.publisher_recognized=false — host OS bridge to unknown companion app.
- broad_host_plus_high_perms manifest http://*/* + https://*/* with webRequest + scripting + nativeMessaging = full-page intercept capability on all sites.
- dom_xss_sinks_no_csp crx 5 innerHTML sinks across content/page scripts; csp_present=false amplifies DOM-XSS risk per FIX B.
- function_constructor_multiple crx function_constructor signal in 6 files (app.js, antiphishing.js, utils.js, content.js, interceptor.js, facebookReactPropsExtractor.js).
- uninstall_url_hijack crx uninstall_url_hijack=true; target null but flag set — +3.0 webstore signal applied.
- sentry_cve_unknown_version crx @sentry/browser version unknown; moderate prototype-pollution CVE, fixed_in 8.33.0 — cannot confirm patched.
- no_csp_mv3 manifest content_security_policy=null; MV3 has strict default for service worker but content scripts lack explicit CSP override.
CVE Exposures (1)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| @sentry/browser@unknown | @sentry/browser@unknown | moderate | 8.33.0 | Sentry SDK Prototype Pollution gadget in JavaScript SDKs |
Permissions Breakdown
- tabs medium Access to tab URLs and metadata across all sites.
- alarms low Background scheduling only.
- storage low Local extension data storage.
- scripting high Injects JS into any page; combined with broad host access is high risk.
- webRequest high Intercepts all HTTP/S requests across all URLs.
- nativeMessaging high Bridges to unrecognized native app; publisher_recognized=false adds risk.
- downloads medium Can trigger and manage file downloads.
- declarativeNetRequest medium Can block/redirect network requests; appropriate for security tool.
- http://*/* high Broad host access to all HTTP sites.
- https://*/* high Broad host access to all HTTPS sites.
Pillar Scores
Permissions8.50
Reputation5.00
Network4.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure1.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:41
Listing SHA
7f751610f720…
Force block
— not fired
Score recovered
no
Elapsed
—