Horizon Forbidden West
djolinogajefpamigdhgfppkifgocici
Risk Score
6.62
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing.
- NewTab override + uninstall URL hijack to play.gameograf.com: game-portal monetization shell pattern.
- 29 months without update; jquery@1.9.1 carries 3 medium XSS CVEs, no CSP amplifies risk.
- Uninstall redirects user to third-party game portal; install also triggers URL hijack.
- 12 distinct external JS hosts including social/CDN origins with no CSP enforcement on MV3 null policy.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://play.gameograf.com/best-games (3rd-party game portal).
- install_url_hijack crx onInstalled opens index.html; pattern consistent with engagement-farming NewTab shells.
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab controlled by extension.
- cve_jquery_1_9_1 crx jquery@1.9.1 has 3 medium XSS CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in 3.5.0.
- stale_extension store Last updated April 2024; 29 months since update with known CVEs unpatched.
- external_js_hosts crx 12 distinct external JS hosts including facebook.com, pinterest.com, twitter.com, gameograf.com.
- no_csp manifest content_security_policy is null; csp_present=false amplifies jQuery XSS CVE risk.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- topSites medium Reads user's most visited sites; NewTab extension can display/exfiltrate this data.
- unlimitedStorage low Allows unlimited local storage; low direct harm but enables caching large payloads.
- storage low Standard local key-value storage; minimal risk alone.
- chrome_url_overrides.newtab high Replaces every new tab; high-reach surface for monetization, tracking, and content injection.
Pillar Scores
Permissions3.50
Reputation6.00
Network4.50
Webstore8.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 06:07
Listing SHA
d02e3e171a1c…
Force block
— not fired
Score recovered
no
Elapsed
—