Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Infinity New Tab

dbfmnekepjoapopniengjbcpnbljalfg
Risk Score
4.86
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category NewTab
Installs 400,000
Rating 4.6
Last updated 2026-07-07 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer infinitynewtab@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (ACE) in bundled underscore@1.8.3 across 400K installs; unfixed.
  • NewTab override contacting 4 search engines (baidu/bing/google/yahoo) — ad-monetization aggregator pattern.
  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension.
  • Multiple new Function() dynamic code execution paths and DOM-XSS innerHTML sinks in extension JS.
  • Free-webmail developer identity (gmail), no developer name, verified publisher discount capped by CVEs.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 carries CVE-2021-23358 (critical ACE) and CVE-2026-27601 (high DoS); fixed_in 1.13.8 not applied.
  • newtab_override_4_search_engines manifest chrome_url_overrides.newtab set; threat_intel shows 4 search engines (baidu, bing, google, yahoo) — ad-monetization aggregator pattern.
  • privacy_policy_not_extension_scoped api Policy fetched but scope_extension==false, data_collection==true, third_party_sharing==true → v3.5 rule D: +10.0 privacy.
  • free_webmail_dev_no_name store developer_email=infinitynewtab@gmail.com; developer_name empty; no verified business identity.
  • function_constructor_and_innerhtml crx Multiple new Function() uses including Vue template compiler and debugger tracer; 4 innerHTML-from-variable DOM-XSS sinks.
  • verified_publisher store verified_publisher==true but cve_findings_raw non-empty → invariant 0c caps discount at -1.0.
  • multi_search_engine_newtab api NewTab category + search_engine_count==4 → +2.5 webstore (v3.5 rule C).
  • 12_external_js_hosts crx 12 distinct external hosts across baidu, bing, yahoo, google subdomains plus infinitynewtab.com own domain.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • activeTab low Access to current tab on user gesture only; limited blast radius.
  • storage low Local data persistence; standard for NewTab extensions.
  • unlimitedStorage low Allows large local storage; minor abuse risk for caching exfil data.
  • offscreen low Offscreen document support; elevated risk only if combined with exfil signals.
  • background low Persistent background context; standard for NewTab but increases dwell time.
  • search medium Can issue search queries programmatically; relevant for search-redirect abuse.
  • chrome_url_overrides.newtab medium Replaces every new tab with extension UI; high reach and monetization surface.

Pillar Scores

Permissions4.50
Reputation6.50
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00

Operator Siblings (1)

Other extensions sharing this developer's compound fingerprint:

Scoring History

<fsssiedxa$"sssiedx 4.23 Medium review 2026-08-11
fsssiedx<sssiedx 4.37 Medium review 2026-08-11
xx pfsssiedxasssiedx 5.47 Medium review 2026-08-05
%27fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.55 Medium review 2026-08-05
4.64 Medium review 2026-08-05
fsssiedxa<sssiedx 4.55 Medium review 2026-08-05
fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.44 Medium review 2026-08-03
fsssiedxa'sssiedx 4.59 Medium review 2026-08-03
sssieddrubricxsx 4.46 Medium review 2026-08-03
v3.6 4.86 Medium block 2026-06-16
v3.4-rev 5.34 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA d860f8f7c277…
Force block — not fired
Score recovered no
Elapsed 55.5s