Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dictionariez: Your Dictionary, Your Language

diojcfpekhhnndfmggknljpnfpcccbhc
Risk Score
4.43
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Other
Installs 6,000
Rating 4.8
Last updated 2026-05-21 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer revir.qing@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • angular@1.8.3 has 1 high + 5 moderate + 3 low CVEs; no fixed version available — library cannot be safely patched.
  • No CSP combined with angular DOM-manipulation lib and high CVEs triggers ×1.5 CVE amplifier (CVE pillar=7.5).
  • eval_user_input (angular.$eval) and script_src_dynamic in multiple bundles enable code execution from external input.
  • Privacy policy admits third-party data sharing but lacks retention disclosure; developer is free-webmail with no dev name.
  • Content scripts injected on <all_urls> with no CSP means XSS escalation surface is every page the user visits.

Evidence

  • angular@1.8.3 CVEs crx 9 CVEs total: CVE-2024-21490 (high), CVE-2023-26116/17/18, CVE-2022-25844/25869, CVE-2025-0716, CVE-2024-8372/73; fixed_in=null.
  • No CSP + angular DOM lib → CVE ×1.5 amplifier manifest content_security_policy is null and angular is a DOM-manipulation lib with high/medium CVEs; amplifier applied.
  • eval_user_input crx dictheader.bundle.js and options.bundle.js call angular.$eval() on variables — direct eval of user-controlled input.
  • script_src_dynamic crx examples.bundle.js dynamically creates <script> elements at runtime — remote code loading vector.
  • free-webmail developer, no dev name store developer_email=revir.qing@gmail.com, developer_name empty; verified_publisher=true, is_featured=true.
  • privacy policy: third_party_sharing=true, retention=false api Policy scoped to extension and acknowledges data collection + 3rd-party sharing but no retention clause.
  • 12 external JS hosts, 3 countries crx Contacts cn.bing.com, wiktionary.org, collinsdictionary.com, oxfordlearnersdictionaries.com etc.; country_count=3.
  • content_scripts <all_urls> + no CSP manifest Scripts run on every URL; absence of CSP removes last-line-of-defence against XSS escalation via CVE-laden angular.

CVE Exposures (9)

CVELibrarySeverity Fixed inSummary
CVE-2023-26117 angular@1.8.3 moderate angular vulnerable to regular expression denial of service via the $resource ser
CVE-2023-26116 angular@1.8.3 moderate angular vulnerable to regular expression denial of service via the angular.copy(
CVE-2024-21490 angular@1.8.3 high angular vulnerable to super-linear runtime due to backtracking
CVE-2025-0716 angular@1.8.3 low AngularJS improperly sanitizes SVG elements
CVE-2022-25844 angular@1.8.3 moderate angular vulnerable to regular expression denial of service (ReDoS)
CVE-2024-8372 angular@1.8.3 low AngularJS allows attackers to bypass common image source restrictions
CVE-2024-8373 angular@1.8.3 low AngularJS allows attackers to bypass common image source restrictions
CVE-2022-25869 angular@1.8.3 moderate Angular (deprecated package) Cross-site Scripting
CVE-2023-26118 angular@1.8.3 moderate angular vulnerable to regular expression denial of service via the <input type="

Permissions Breakdown

  • activeTab low Scoped to user-activated tab only; limited blast radius.
  • tabs medium Can read tab URLs and metadata across open tabs.
  • storage low Local data persistence; low standalone risk.
  • contextMenus low UI integration only; no data access.
  • offscreen low Allows off-screen document; moderate capability but no host access.
  • content_scripts:<all_urls> high Scripts injected into every page; broad reach combined with tabs elevates risk.

Pillar Scores

Permissions3.30
Reputation4.50
Network4.50
Webstore1.00
Maintenance0.00
Privacy2.00
Code Quality7.50
CVE Exposure7.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA 6cb2cf8f78d0…
Force block — not fired
Score recovered no
Elapsed 43.8s