Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screenshot and screen video recording - Screeny

djekgpcemgcnfkjldcclcpcjhemofcib
Risk Score
7.63
Risk Level: High
Recommendation: 🚫 BLOCK
Category Screenshot
Installs 80,000
Rating 4.7
Last updated 2025-02-20 (18 months ago)
Manifest version MV3
CSP present ✅ yes
Developer eugenijs98saulite@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critically outdated JS libs: lodash+underscore with critical CVEs (prototype pollution, arbitrary code exec) bundled in extension injected on all sites.
  • Privacy policy URL timed out (fetch_error) — effectively no verifiable privacy policy; scored as unfetched (+10.0).
  • Developer uses free Gmail with no developer name listed; verified_publisher present but v3.5 invariant 0c caps discount due to stale+CVEs.
  • Extension has been 18 months without update while bundling multiple high/critical severity vulnerable libraries across jquery, lodash, moment, underscore.
  • <all_urls> content script injection paired with vulnerable DOM-manipulation libraries (jquery, underscore) raises XSS escalation risk on every visited page.

Evidence

  • critical_cve_lodash crx lodash CVE-2019-10744 critical prototype pollution; underscore 1.8.3 CVE-2021-23358 arbitrary code exec (critical).
  • high_cve_count crx 4 high-severity CVEs across lodash (x2), moment (x2); 7+ medium CVEs across jquery, lodash, moment.
  • privacy_policy_timeout api fetch_error:ConnectTimeout on https://getscreeny.com/?p=privacy_policy — policy unverifiable.
  • stale_extension store 18 months since last update; invariant 0c triggers: CVEs present + stale >18mo caps verified-publisher discount to -1.0.
  • broad_host_access manifest <all_urls> in permissions + content_scripts_matches; content scripts injected on every site.
  • free_webmail_dev store Developer email eugenijs98saulite@gmail.com; no developer name; free Gmail account.
  • verified_and_featured store verified_publisher=true and is_featured_by_google=true; discounts apply but capped by invariant 0c.
  • js_external_hosts_docs_only crx js_external_hosts are documentation domains (mozilla.org, jquery.com etc.) — no active CDN risk.

CVE Exposures (15)

CVELibrarySeverity Fixed inSummary
CVE-2012-6708 jquery@unknown moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2011-4969 jquery@unknown moderate 1.6.3 jQuery vulnerable to Cross-Site Scripting (XSS)
CVE-2015-9251 jquery@unknown moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2021-23337 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2026-4800 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2018-16487 lodash@unknown high 4.17.11 Prototype Pollution in lodash
CVE-2025-13465 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2026-2950 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2018-3721 lodash@unknown moderate 4.17.5 Prototype Pollution in lodash
CVE-2019-10744 lodash@unknown critical 4.17.12 Prototype Pollution in lodash
CVE-2017-18214 moment@unknown high 2.19.3 Regular Expression Denial of Service in moment
CVE-2016-4055 moment@unknown moderate 2.11.2 Regular Expression Denial of Service in moment
CVE-2022-24785 moment@unknown high 2.29.2 Path Traversal: 'dir/../../filename' in moment.locale
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata across all tabs.
  • <all_urls> high Broad host access enabling content script injection on every site.
  • activeTab low Scoped to current tab on user action; low residual risk.
  • storage low Local extension data storage.
  • unlimitedStorage low Larger quota; needed for video/screenshot files.
  • alarms low Scheduled background tasks.
  • desktopCapture medium Can capture full screen, windows, or tabs — core to stated function but sensitive.
  • identity low OAuth token access; no scopes declared, lower risk.

Pillar Scores

Permissions4.50
Reputation3.50
Network0.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure10.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:49
Listing SHA 818116611fa6…
Force block — not fired
Score recovered no
Elapsed