Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Turbo Downloader for Instagram

cpgaheeihidjmolbakklolchdplenjai
Risk Score
6.78
Risk Level: High
Recommendation: 🚫 BLOCK
Category MediaDownloader
Installs 700,000
Rating 3.5
Last updated
Manifest version MV3
CSP present ❌ no
Developer igdownload2023@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Instagram brand impersonation by unverified gmail developer; uninstall URL hijack detected.
  • No last_updated date available — maintenance unknowable; treated as maximum staleness risk.
  • Two innerHTML DOM-XSS sinks with no CSP, amplifying XSS risk against 600K installs on Instagram.
  • Description promises download but lacks 'downloads' permission — permission/function mismatch.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is unverified gmail account igdownload2023@gmail.com.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension redirects to 3rd-party URL on uninstall.
  • generic_privacy_policy store Privacy policy is Google's own account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • no_csp crx content_security_policy=null; MV3 with no explicit CSP and DOM-XSS sinks present.
  • dom_xss_sinks crx Two dom_sink_innerhtml_userctrl findings in extension.js and options.js; no CSP hardening.
  • maintenance_unknown store last_updated and months_since_update are null; update history unverifiable — scored at maximum.
  • description_permission_mismatch store description_promise mismatch: promises download but lacks 'downloads' permission.
  • free_webmail_developer store Developer email igdownload2023@gmail.com; no business website; numbered-alias pattern.

Permissions Breakdown

  • storage low Stores extension preferences locally; minimal risk.
  • *://*.instagram.com/* high Broad host access to Instagram; content scripts injected here enabling page-read.
  • *://*.cdninstagram.com/* medium Access to Instagram CDN for media fetch; in-scope for downloader but still elevated.
  • *://*.cdninstagram.net/* medium Secondary Instagram CDN domain; same rationale as cdninstagram.com.
  • *://*.fbcdn.net/* medium Facebook CDN used by Instagram; broadens cross-domain reach beyond stated scope.

Pillar Scores

Permissions3.50
Reputation8.00
Network0.00
Webstore8.50
Maintenance10.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Scoring History

sssiednf9ea667fdp727562726963xsx 6.75 High block 2026-09-09
sssiedn044b37f3dp727562726963xsx 6.71 High block 2026-09-02
v3.6 6.78 High block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA 943a4e85d0f1…
Force block — not fired
Score recovered no
Elapsed 23.8s