Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cookie Backup and Restore

cndobhdcpmpilkebeebeecgminfhkpcj
Risk Score
6.44
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Security
Installs 10,000
Rating 4.7
Last updated 2023-01-17 (41 months ago)
Manifest version MV3
CSP present ❌ no
Developer khichihaider@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies+<all_urls> with no CSP: can read/exfil all cookies from every site if compromised.
  • Extension is 41 months stale (>36mo) — zombie with 10K installs; high acquisition-attack value.
  • Privacy policy is Google's generic account policy — no scope to this extension; data handling unknown.
  • Developer uses free Gmail with no business domain; no verified-publisher badge.
  • DOM-XSS sink (innerHTML) in popup.js with no CSP increases exploit surface if cookie data rendered.

Evidence

  • cookies+<all_urls> high-perm combo manifest cookies + <all_urls> → ×1.2 multiplier applied; full cookie access on all sites.
  • no CSP declared crx csp_present=false and content_security_policy=null; MV3 default applies but DOM-XSS sink present.
  • stale extension >36 months store Last updated January 17 2023; 41 months since update; zombie booster +1.0 at 10K installs.
  • gmail developer, no business domain store developer_email=khichihaider@gmail.com; brand_mention.developer_domain=gmail.com; free-webmail dev.
  • generic Google privacy policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
  • dom_sink_innerhtml_userctrl crx popup.js: innerHTML assigned from variable with no CSP; triggers +2.0 FIX B.
  • is_featured_by_google=true store Featured badge provides -2.0 reputation discount despite stale state and gmail dev.
  • triple-stale fingerprint (v3.2b) store >24mo + MV3 (no CVEs) + no CSP; +2.0 webstore triple-stale applied.

Permissions Breakdown

  • cookies high Full cookie read/write across all origins; paired with <all_urls> multiplies risk ×1.2.
  • downloads medium Can write files to disk; used legitimately here for backup export.
  • <all_urls> high Broad host access enabling cookie exfil on every site the user visits.

Pillar Scores

Permissions7.00
Reputation6.50
Network0.00
Webstore1.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA 0517f9362cc4…
Force block — not fired
Score recovered no
Elapsed 24.9s