Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ImageAssistant Batch Image Downloader

dbjbempljhcmhlfpfacalomonjpalpko
Risk Score
5.71
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 600,000
Rating 4.3
Last updated 2024-10-23 (23 months ago)
Manifest version MV3
CSP present ❌ no
Developer netactspcl@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); not patched.
  • High CVE-2026-27601 + 2 medium jQuery XSS CVEs; no CSP amplifies DOM-XSS risk.
  • webRequest + declarativeNetRequestWithHostAccess + <all_urls> gives full request interception on every site.
  • Developer uses free Gmail with no verified business identity; no developer name listed.
  • Privacy policy admits third-party data sharing but lacks retention disclosure; stale >18mo.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical); fixed in 1.12.1 — not updated.
  • high_cve_underscore crx underscore@1.8.3 has CVE-2026-27601 (high DoS via recursion); fixed in 1.13.8.
  • medium_cves_jquery crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (XSS); fixed in 3.5.0.
  • no_csp_amplifier manifest No content_security_policy; DOM-XSS sink (innerHTML) in bootstrap + jQuery CVEs = amplified risk.
  • high_perm_all_urls_webrequest manifest webRequest + declarativeNetRequestWithHostAccess + <all_urls> + scripting = full request/content control.
  • free_webmail_no_dev_name store Dev email netactspcl@gmail.com; no developer name; free webmail with no verified business domain.
  • privacy_third_party_sharing api Privacy policy: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • stale_20mo store Last updated Oct 2024, 20 months stale; CVEs present; verified publisher cap applies (0c).

CVE Exposures (8)

CVELibrarySeverity Fixed inSummary
CVE-2017-20165 debug@unknown high 3.1.0 debug Inefficient Regular Expression Complexity vulnerability
CVE-2017-16137 debug@unknown low 2.6.9 Regular Expression Denial of Service in debug
querystringify@unknown querystringify@unknown high 2.0.0 Prototype Pollution in querystringify
CVE-2022-0686 url-parse@unknown critical 1.5.8 Authorization Bypass Through User-Controlled Key in url-parse
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Access to tab URLs/titles; needed for image discovery across pages.
  • scripting medium Inject scripts into pages; broad capability paired with <all_urls>.
  • webNavigation medium Observe navigation events; used to detect image-bearing pages.
  • webRequest high Intercept/observe all network requests; high capability.
  • declarativeNetRequest medium Block/redirect requests declaratively; moderate risk.
  • declarativeNetRequestWithHostAccess high Modify requests on all hosts; elevates declarativeNetRequest to high.
  • storage low Local settings persistence; low risk.
  • downloads medium Trigger file downloads; core to stated function.
  • notifications low Show desktop notifications; low risk.
  • contextMenus low Right-click menu entries; low risk.
  • fontSettings low Read/write browser font settings; low risk, unusual for a downloader.
  • <all_urls> (host) high Full cross-origin access; combined with webRequest/scripting raises capability significantly.

Pillar Scores

Permissions5.50
Reputation7.50
Network4.00
Webstore3.00
Maintenance6.00
Privacy2.00
Code Quality2.00
CVE Exposure9.00

Scoring History

fsssiedxx'sssiedx 6.24 High review 2026-07-28
v3.6 5.71 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA 6f1e1a2e5df6…
Force block — not fired
Score recovered no
Elapsed 31.2s