Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Horizon Forbidden West

djolinogajefpamigdhgfppkifgocici
Risk Score
6.62
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 305
Rating 4.4
Last updated 2024-04-15 (29 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing.
  • NewTab override + uninstall URL hijack to play.gameograf.com: game-portal monetization shell pattern.
  • 29 months without update; jquery@1.9.1 carries 3 medium XSS CVEs, no CSP amplifies risk.
  • Uninstall redirects user to third-party game portal; install also triggers URL hijack.
  • 12 distinct external JS hosts including social/CDN origins with no CSP enforcement on MV3 null policy.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://play.gameograf.com/best-games (3rd-party game portal).
  • install_url_hijack crx onInstalled opens index.html; pattern consistent with engagement-farming NewTab shells.
  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab controlled by extension.
  • cve_jquery_1_9_1 crx jquery@1.9.1 has 3 medium XSS CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in 3.5.0.
  • stale_extension store Last updated April 2024; 29 months since update with known CVEs unpatched.
  • external_js_hosts crx 12 distinct external JS hosts including facebook.com, pinterest.com, twitter.com, gameograf.com.
  • no_csp manifest content_security_policy is null; csp_present=false amplifies jQuery XSS CVE risk.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • topSites medium Reads user's most visited sites; NewTab extension can display/exfiltrate this data.
  • unlimitedStorage low Allows unlimited local storage; low direct harm but enables caching large payloads.
  • storage low Standard local key-value storage; minimal risk alone.
  • chrome_url_overrides.newtab high Replaces every new tab; high-reach surface for monetization, tracking, and content injection.

Pillar Scores

Permissions3.50
Reputation6.00
Network4.50
Webstore8.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 06:07
Listing SHA d02e3e171a1c…
Force block — not fired
Score recovered no
Elapsed