Web Color Picker - online color grabber
dneifdhdmnmmlobjbimlkcnhkbidmlek
Risk Score
7.28
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical + high CVEs in bundled lodash/jquery at unknown versions with no CSP; DOM-manipulation libs without policy amplifier applied.
- Uninstall and install URL hijacks flagged — monetization/tracking behaviour on install and removal lifecycle.
- Privacy policy is Google's generic account policy — not scoped to this extension; collects and shares data with third parties.
- webRequest + *://*/* content scripts allow observation and manipulation of all browser traffic across every site.
- Free webmail developer email (outlook.com), no verified publisher, 17-month stale extension with active CVE exposure.
Evidence
- cve_critical_lodash crx CVE-2019-10744 critical prototype pollution in lodash and lodash-es at unknown versions bundled in popup.js.
- cve_high_lodash_jquery crx Multiple high-severity CVEs: CVE-2021-23337 (command injection lodash), CVE-2018-16487, CVE-2018-3721; moderate jQuery XSS CVEs.
- cve_amplifier_no_csp crx No CSP present + high/medium CVEs in lodash (DOM-manipulation lib) → ×1.5 CVE amplifier applied (cap 10).
- uninstall_install_hijack crx Both uninstall_url_hijack and install_url_hijack are true — lifecycle event hooking for tracking/monetization.
- privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; data_collection+third_party_sharing=true.
- webRequest_broad_host manifest webRequest declared alongside *://*/* host_permissions and content_scripts — intercepts all traffic on all sites.
- free_webmail_developer store Developer email pickercolor@outlook.com is free webmail; no verified publisher badge; no business domain.
- dom_sink_innerhtml crx scripts/options.js: innerHTML assigned from variable — DOM-XSS sink with no CSP guard.
CVE Exposures (15)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23337 | lodash-es@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2026-4800 | lodash-es@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2025-13465 | lodash-es@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2026-2950 | lodash-es@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2019-10744 | lodash-es@unknown | critical | 4.17.14 | Prototype Pollution in lodash |
| CVE-2021-23337 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2026-4800 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2018-16487 | lodash@unknown | high | 4.17.11 | Prototype Pollution in lodash |
| CVE-2025-13465 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2026-2950 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2018-3721 | lodash@unknown | moderate | 4.17.5 | Prototype Pollution in lodash |
| CVE-2019-10744 | lodash@unknown | critical | 4.17.12 | Prototype Pollution in lodash |
| CVE-2012-6708 | jquery@unknown | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2011-4969 | jquery@unknown | moderate | 1.6.3 | jQuery vulnerable to Cross-Site Scripting (XSS) |
| CVE-2015-9251 | jquery@unknown | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- activeTab low Scoped to user-initiated tab interaction only.
- notifications medium Can push notifications; minor abuse vector.
- storage low Local data persistence; low standalone risk.
- webRequest high Can observe all network requests across all URLs.
- contextMenus low Adds right-click menu items; low risk.
- commands low Keyboard shortcut binding; low risk.
- *://*/* high Broad host access — content scripts injected into every site.
Pillar Scores
Permissions7.00
Reputation7.00
Network4.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure10.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:08
Listing SHA
f6edb1945812…
Force block
— not fired
Score recovered
no
Elapsed
—