Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DeepSider™:AI Sidebar | DeepSeek, Gemini, Claude, GPT

dfbnddndcmilnhdfmmaolepiaefacnpo
Risk Score
4.74
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category AI
Installs 200,000
Rating 4.8
Last updated 2026-08-25 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer deepsiderpro@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution) plus high-severity DoS CVE; unfixed.
  • Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — admits broad data sharing without extension scoping.
  • Impersonates Claude/DeepSeek/Gemini brands without verified ownership; developer uses free Gmail.
  • Multiple function_constructor + dynamic script creation signals across 8+ bundles; innerHTML DOM-XSS sinks in content.js.
  • CSP connect-src allows https://* http://* (effectively open); 5-country geo-diversity including CN-hosted Aliyun/Tencent COS endpoints.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 carries CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); both unfixed at bundled version.
  • privacy_policy_generic_with_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) triggers +10.0 privacy score.
  • brand_impersonation store Title mentions Claude, DeepSeek, Gemini; confirmed_owner=false, developer_email=gmail.com → +2.0 reputation.
  • free_webmail_developer store Developer email deepsiderpro@gmail.com; no verified business identity; triggers +1.5 reputation penalty.
  • csp_connect_src_open crx connect-src includes https://* http://* — allows exfil to any HTTPS/HTTP host; +2.5 network.
  • cn_cloud_storage_endpoints crx JS contacts Aliyun OSS (Beijing) and Tencent COS (Guangzhou); 5-country geo-diversity triggers +1.5 network.
  • code_function_constructor_and_dynamic_script crx function_constructor in 8 files (+2.5), script_src_dynamic in 4 files (+3.0), innerHTML DOM-XSS sinks in 3 files.
  • ai_extension_page_content store AI sidebar extension processing page content (+2.5 webstore) with 200K installs (+1.0+1.0 webstore).

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • sidePanel low Displays side panel UI; no cross-site data access.
  • storage low Local extension storage only.
  • scripting medium Can inject scripts into pages; risk depends on host access scope.

Pillar Scores

Permissions1.30
Reputation5.50
Network5.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality7.50
CVE Exposure7.00

Scoring History

sssiedn1d1c43c8dp727562726963xsx 5.11 Medium block 2026-09-09
v3.6 4.74 Medium block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 06:00
Listing SHA c8b9a5f38fa8…
Force block — not fired
Score recovered no
Elapsed 37.4s