Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web Color Picker - online color grabber

dneifdhdmnmmlobjbimlkcnhkbidmlek
Risk Score
7.28
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 30,000
Rating 4.0
Last updated 2025-03-18 (17 months ago)
Manifest version MV3
CSP present ❌ no
Developer pickercolor@outlook.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical + high CVEs in bundled lodash/jquery at unknown versions with no CSP; DOM-manipulation libs without policy amplifier applied.
  • Uninstall and install URL hijacks flagged — monetization/tracking behaviour on install and removal lifecycle.
  • Privacy policy is Google's generic account policy — not scoped to this extension; collects and shares data with third parties.
  • webRequest + *://*/* content scripts allow observation and manipulation of all browser traffic across every site.
  • Free webmail developer email (outlook.com), no verified publisher, 17-month stale extension with active CVE exposure.

Evidence

  • cve_critical_lodash crx CVE-2019-10744 critical prototype pollution in lodash and lodash-es at unknown versions bundled in popup.js.
  • cve_high_lodash_jquery crx Multiple high-severity CVEs: CVE-2021-23337 (command injection lodash), CVE-2018-16487, CVE-2018-3721; moderate jQuery XSS CVEs.
  • cve_amplifier_no_csp crx No CSP present + high/medium CVEs in lodash (DOM-manipulation lib) → ×1.5 CVE amplifier applied (cap 10).
  • uninstall_install_hijack crx Both uninstall_url_hijack and install_url_hijack are true — lifecycle event hooking for tracking/monetization.
  • privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; data_collection+third_party_sharing=true.
  • webRequest_broad_host manifest webRequest declared alongside *://*/* host_permissions and content_scripts — intercepts all traffic on all sites.
  • free_webmail_developer store Developer email pickercolor@outlook.com is free webmail; no verified publisher badge; no business domain.
  • dom_sink_innerhtml crx scripts/options.js: innerHTML assigned from variable — DOM-XSS sink with no CSP guard.

CVE Exposures (15)

CVELibrarySeverity Fixed inSummary
CVE-2021-23337 lodash-es@unknown high 4.17.21 Command Injection in lodash
CVE-2026-4800 lodash-es@unknown high 4.17.21 Command Injection in lodash
CVE-2025-13465 lodash-es@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2026-2950 lodash-es@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2019-10744 lodash-es@unknown critical 4.17.14 Prototype Pollution in lodash
CVE-2021-23337 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2026-4800 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2018-16487 lodash@unknown high 4.17.11 Prototype Pollution in lodash
CVE-2025-13465 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2026-2950 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2018-3721 lodash@unknown moderate 4.17.5 Prototype Pollution in lodash
CVE-2019-10744 lodash@unknown critical 4.17.12 Prototype Pollution in lodash
CVE-2012-6708 jquery@unknown moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2011-4969 jquery@unknown moderate 1.6.3 jQuery vulnerable to Cross-Site Scripting (XSS)
CVE-2015-9251 jquery@unknown moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab interaction only.
  • notifications medium Can push notifications; minor abuse vector.
  • storage low Local data persistence; low standalone risk.
  • webRequest high Can observe all network requests across all URLs.
  • contextMenus low Adds right-click menu items; low risk.
  • commands low Keyboard shortcut binding; low risk.
  • *://*/* high Broad host access — content scripts injected into every site.

Pillar Scores

Permissions7.00
Reputation7.00
Network4.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure10.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:08
Listing SHA f6edb1945812…
Force block — not fired
Score recovered no
Elapsed