Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

HiTab - New Tab Dashboard and Widgets

doeomodlafdbbnajjllemacdfphbbohl
Risk Score
6.81
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 5,000
Rating 3.4
Last updated 2025-01-11 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer hitabpro@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); no CSP amplifies ×1.5 CVE pillar.
  • No content_security_policy; dynamic script injection and new Function() calls can execute arbitrary code with no sandbox.
  • Privacy policy fetched but not scoped to this extension despite admitting data collection; +10 privacy score.
  • Free webmail dev email (hitabpro@gmail.com), no developer name, no verified publisher; accountability gap.
  • NewTab override with broad *://* host_permissions contacts Baidu analytics/CDN and Yandex — cross-border data exposure.

Evidence

  • CVE critical: underscore@1.8.3 CVE-2021-23358 arbitrary code execution; no CSP present → ×1.5 amplifier crx underscore 1.8.3 fixed in 1.12.1; CVE-2026-27601 high severity DoS also present; both unpatched.
  • code_finding: script_src_dynamic + function_constructor × 4 files crx Dynamic <script> creation and new Function() found in hm.js, popup, and bundled assets; no CSP guard.
  • dom_sink_innerhtml_userctrl with no CSP and CVEs present → +2.0 code quality crx Two innerHTML sinks from variables found; csp_present==false and cve_findings nonempty trigger FIX B.
  • Privacy policy scope_extension==false AND data_collection==true AND third_party_sharing==false api Policy is generic (hitab.me) and does not scope to this extension; +10 privacy per v3 FIX A.
  • Free webmail dev email, no developer name, no verified publisher badge store hitabpro@gmail.com; developer_name empty; reputation floor raised to 7.0.
  • js_external_hosts include tongji.baidu.com, fclog.baidu.com, hmcdn.baidu.com, www.yandex.ru crx 3 Baidu analytics/CDN endpoints + Yandex; 3 distinct countries (CA, CN, US); geo-diversity concern.
  • NewTab override with *://* host_permissions; months_since_update=19 manifest Broad host access for a NewTab/dashboard extension; stale 19 months triggers active+partial maintenance penalty.
  • install_perm_anomaly.tail_attack_surface == true api 5,000 installs with broad host permissions and NewTab override; tail-attack-surface flag set.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • activeTab low Scoped to user-initiated interaction; limited blast radius.
  • storage low Local settings persistence; no cross-origin data access.
  • unlimitedStorage low Allows large local cache; no network exfil on its own.
  • host_permissions: *://*/* high Broad host access to all URLs; combined with NewTab override elevates reach significantly.
  • chrome_url_overrides: newtab medium Replaces every new tab with extension page; high-reach surface hijack.

Pillar Scores

Permissions5.50
Reputation7.00
Network5.50
Webstore6.50
Maintenance6.00
Privacy10.00
Code Quality7.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:50
Listing SHA 1ee802bd1946…
Force block — not fired
Score recovered no
Elapsed