Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GifMatic- Gif Maker for Chrome™

eaddimhcnmjhmemoaaidmgolgioifgeg
Risk Score
5.83
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs
Rating
Last updated 2025-01-30 (17 months ago)
Manifest version MV3
CSP present ❌ no
Developer campdavid1337@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; no CSP amplifies risk.
  • No CSP + new Function() constructor in tui-color-picker.js enables dynamic code execution.
  • Two innerHTML DOM-XSS sinks with no CSP increase exploitability of CVE-amplified attack surface.
  • Privacy policy is Google's own generic policy (not scoped to this extension), admitting data collection and 3rd-party sharing.
  • Developer uses free Gmail address with no verified business identity; extension is 17 months stale.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (Arbitrary Code Execution, critical); fixed in 1.12.1.
  • high_cve_bundled_lib crx underscore@1.8.3 also carries CVE-2026-27601 (DoS via unlimited recursion, high); fixed in 1.13.8.
  • no_csp_with_function_constructor crx csp_present=false; new Function() in tui-color-picker.js; MV3 but no declared CSP in manifest.
  • dom_xss_sinks crx innerHTML used with variable input in two files (tui-color-picker.js, index.js); no CSP to mitigate.
  • generic_google_privacy_policy store Privacy URL points to myaccount.google.com — not scoped to this extension; admits data collection and 3rd-party sharing.
  • free_webmail_developer store Developer email campdavid1337@gmail.com; no verified business domain; domain_age_ct not queryable.
  • stale_extension store Last updated January 30, 2025 (17 months ago); CVEs unfixed; maintenance score elevated.
  • content_script_narrow_origin manifest content_scripts_matches scoped to puzzle-generator-online-r906.onrender.com/donate/* only; narrow.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Access to tab URLs/titles; medium risk for a screen-capture GIF tool.
  • storage low Local key-value storage; low risk, standard for saving settings.
  • desktopCapture medium Captures screen/window content; expected for a GIF recorder but sensitive.
  • unlimitedStorage low Removes storage quota; low risk, reasonable for GIF/video data.

Pillar Scores

Permissions3.30
Reputation7.50
Network2.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality7.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA 7d81d67600d0…
Force block — not fired
Score recovered no
Elapsed 28.8s