Infinity New Tab
dbfmnekepjoapopniengjbcpnbljalfg
Risk Score
4.86
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 (ACE) in bundled underscore@1.8.3 across 400K installs; unfixed.
- NewTab override contacting 4 search engines (baidu/bing/google/yahoo) — ad-monetization aggregator pattern.
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension.
- Multiple new Function() dynamic code execution paths and DOM-XSS innerHTML sinks in extension JS.
- Free-webmail developer identity (gmail), no developer name, verified publisher discount capped by CVEs.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 carries CVE-2021-23358 (critical ACE) and CVE-2026-27601 (high DoS); fixed_in 1.13.8 not applied.
- newtab_override_4_search_engines manifest chrome_url_overrides.newtab set; threat_intel shows 4 search engines (baidu, bing, google, yahoo) — ad-monetization aggregator pattern.
- privacy_policy_not_extension_scoped api Policy fetched but scope_extension==false, data_collection==true, third_party_sharing==true → v3.5 rule D: +10.0 privacy.
- free_webmail_dev_no_name store developer_email=infinitynewtab@gmail.com; developer_name empty; no verified business identity.
- function_constructor_and_innerhtml crx Multiple new Function() uses including Vue template compiler and debugger tracer; 4 innerHTML-from-variable DOM-XSS sinks.
- verified_publisher store verified_publisher==true but cve_findings_raw non-empty → invariant 0c caps discount at -1.0.
- multi_search_engine_newtab api NewTab category + search_engine_count==4 → +2.5 webstore (v3.5 rule C).
- 12_external_js_hosts crx 12 distinct external hosts across baidu, bing, yahoo, google subdomains plus infinitynewtab.com own domain.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab low Access to current tab on user gesture only; limited blast radius.
- storage low Local data persistence; standard for NewTab extensions.
- unlimitedStorage low Allows large local storage; minor abuse risk for caching exfil data.
- offscreen low Offscreen document support; elevated risk only if combined with exfil signals.
- background low Persistent background context; standard for NewTab but increases dwell time.
- search medium Can issue search queries programmatically; relevant for search-redirect abuse.
- chrome_url_overrides.newtab medium Replaces every new tab with extension UI; high reach and monetization surface.
Pillar Scores
Permissions4.50
Reputation6.50
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00
Operator Siblings (1)
Other extensions sharing this developer's compound fingerprint:
Scoring History
| <fsssiedxa$"sssiedx | 4.23 | Medium | review | 2026-08-11 |
| fsssiedx<sssiedx | 4.37 | Medium | review | 2026-08-11 |
| xx pfsssiedxasssiedx | 5.47 | Medium | review | 2026-08-05 |
| %27fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.55 | Medium | review | 2026-08-05 |
| 4.64 | Medium | review | 2026-08-05 | |
| fsssiedxa<sssiedx | 4.55 | Medium | review | 2026-08-05 |
| fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.44 | Medium | review | 2026-08-03 |
| fsssiedxa'sssiedx | 4.59 | Medium | review | 2026-08-03 |
| sssieddrubricxsx | 4.46 | Medium | review | 2026-08-03 |
| v3.6 | 4.86 | Medium | block | 2026-06-16 |
| v3.4-rev | 5.34 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
d860f8f7c277…
Force block
— not fired
Score recovered
no
Elapsed
55.5s