HiTab - New Tab Dashboard and Widgets
doeomodlafdbbnajjllemacdfphbbohl
Risk Score
6.81
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); no CSP amplifies ×1.5 CVE pillar.
- No content_security_policy; dynamic script injection and new Function() calls can execute arbitrary code with no sandbox.
- Privacy policy fetched but not scoped to this extension despite admitting data collection; +10 privacy score.
- Free webmail dev email (hitabpro@gmail.com), no developer name, no verified publisher; accountability gap.
- NewTab override with broad *://* host_permissions contacts Baidu analytics/CDN and Yandex — cross-border data exposure.
Evidence
- CVE critical: underscore@1.8.3 CVE-2021-23358 arbitrary code execution; no CSP present → ×1.5 amplifier crx underscore 1.8.3 fixed in 1.12.1; CVE-2026-27601 high severity DoS also present; both unpatched.
- code_finding: script_src_dynamic + function_constructor × 4 files crx Dynamic <script> creation and new Function() found in hm.js, popup, and bundled assets; no CSP guard.
- dom_sink_innerhtml_userctrl with no CSP and CVEs present → +2.0 code quality crx Two innerHTML sinks from variables found; csp_present==false and cve_findings nonempty trigger FIX B.
- Privacy policy scope_extension==false AND data_collection==true AND third_party_sharing==false api Policy is generic (hitab.me) and does not scope to this extension; +10 privacy per v3 FIX A.
- Free webmail dev email, no developer name, no verified publisher badge store hitabpro@gmail.com; developer_name empty; reputation floor raised to 7.0.
- js_external_hosts include tongji.baidu.com, fclog.baidu.com, hmcdn.baidu.com, www.yandex.ru crx 3 Baidu analytics/CDN endpoints + Yandex; 3 distinct countries (CA, CN, US); geo-diversity concern.
- NewTab override with *://* host_permissions; months_since_update=19 manifest Broad host access for a NewTab/dashboard extension; stale 19 months triggers active+partial maintenance penalty.
- install_perm_anomaly.tail_attack_surface == true api 5,000 installs with broad host permissions and NewTab override; tail-attack-surface flag set.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab low Scoped to user-initiated interaction; limited blast radius.
- storage low Local settings persistence; no cross-origin data access.
- unlimitedStorage low Allows large local cache; no network exfil on its own.
- host_permissions: *://*/* high Broad host access to all URLs; combined with NewTab override elevates reach significantly.
- chrome_url_overrides: newtab medium Replaces every new tab with extension page; high-reach surface hijack.
Pillar Scores
Permissions5.50
Reputation7.00
Network5.50
Webstore6.50
Maintenance6.00
Privacy10.00
Code Quality7.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:50
Listing SHA
1ee802bd1946…
Force block
— not fired
Score recovered
no
Elapsed
—