GifMatic- Gif Maker for Chrome™
eaddimhcnmjhmemoaaidmgolgioifgeg
Risk Score
5.83
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; no CSP amplifies risk.
- No CSP + new Function() constructor in tui-color-picker.js enables dynamic code execution.
- Two innerHTML DOM-XSS sinks with no CSP increase exploitability of CVE-amplified attack surface.
- Privacy policy is Google's own generic policy (not scoped to this extension), admitting data collection and 3rd-party sharing.
- Developer uses free Gmail address with no verified business identity; extension is 17 months stale.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (Arbitrary Code Execution, critical); fixed in 1.12.1.
- high_cve_bundled_lib crx underscore@1.8.3 also carries CVE-2026-27601 (DoS via unlimited recursion, high); fixed in 1.13.8.
- no_csp_with_function_constructor crx csp_present=false; new Function() in tui-color-picker.js; MV3 but no declared CSP in manifest.
- dom_xss_sinks crx innerHTML used with variable input in two files (tui-color-picker.js, index.js); no CSP to mitigate.
- generic_google_privacy_policy store Privacy URL points to myaccount.google.com — not scoped to this extension; admits data collection and 3rd-party sharing.
- free_webmail_developer store Developer email campdavid1337@gmail.com; no verified business domain; domain_age_ct not queryable.
- stale_extension store Last updated January 30, 2025 (17 months ago); CVEs unfixed; maintenance score elevated.
- content_script_narrow_origin manifest content_scripts_matches scoped to puzzle-generator-online-r906.onrender.com/donate/* only; narrow.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- tabs medium Access to tab URLs/titles; medium risk for a screen-capture GIF tool.
- storage low Local key-value storage; low risk, standard for saving settings.
- desktopCapture medium Captures screen/window content; expected for a GIF recorder but sensitive.
- unlimitedStorage low Removes storage quota; low risk, reasonable for GIF/video data.
Pillar Scores
Permissions3.30
Reputation7.50
Network2.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality7.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
7d81d67600d0…
Force block
— not fired
Score recovered
no
Elapsed
28.8s