Adobe Acrobat: PDF edit, convert, sign tools
efaidnbmnnnibpcajpcglclefindmkaj
Risk Score
4.82
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetch failed (timeout); treated as no policy — score 10.0 on privacy pillar.
- nativeMessaging declared but companion-app publisher not recognized, enabling local system bridge.
- jquery@3.1.1 bundles 3 moderate CVEs (XSS); fixed versions available (3.4.0/3.5.0) — library not updated.
- cookies + <all_urls> + webRequest + scripting combination grants broad read/write capability across every site.
- 6 innerHTML DOM-XSS sinks in content scripts active on <all_urls>; CVEs present amplify XSS surface.
Evidence
- privacy_policy_fetch_failed api Privacy policy URL present but fetch timed out; classified as fetched=false → pillar scores 10.0.
- native_messaging_unrecognized_publisher crx nativeMessaging declared; native_messaging_check.publisher_recognized=false.
- jquery_cve_bundle crx jquery@3.1.1 bundles CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all moderate); fixed_in 3.5.0.
- broad_host_access_high_perms manifest cookies+webRequest+scripting+<all_urls>; ×1.2 amplifier applied to permissions pillar.
- dom_xss_sinks crx 6 innerHTML-from-variable findings in content scripts running on <all_urls>; CVEs present → FIX B applies (+2.0).
- featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied; floor 2.0 enforced.
- large_install_base store 328M installs; +1.0+1.0+0.5 webstore; -0.5 popularity-trust discount applied.
- recently_updated store months_since_update=0; maintenance pillar=0.0.
CVE Exposures (1)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2025-2792 | @mozilla/readability@unknown | low | 0.6.0 | @mozilla/readability Denial of Service through Regex |
Permissions Breakdown
- contextMenus low Adds right-click menu items; low standalone risk.
- tabs medium Can read tab URLs and titles across all open tabs.
- downloads medium Can intercept and manage file downloads.
- nativeMessaging high Communicates with native Adobe desktop app; publisher_recognized=false raises concern.
- webRequest high Can observe all HTTP requests across all URLs (paired with <all_urls>).
- webNavigation medium Tracks navigation events across tabs.
- storage low Local/sync data storage; minimal standalone risk.
- scripting high Can inject scripts into any page given <all_urls> host permission.
- alarms low Schedules background tasks; low risk.
- offscreen low Creates offscreen documents for background processing.
- cookies high Can read/write cookies for all sites paired with <all_urls>; ×1.2 amplifier applies.
- sidePanel low Renders UI in browser side panel.
- declarativeNetRequest medium Can block/redirect network requests declaratively.
- fileSystem medium Access to local file system entries.
- <all_urls> high Broad host access covering every site; amplifies cookies, webRequest, scripting.
Pillar Scores
Permissions7.50
Reputation2.00
Network3.50
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure3.75
Scoring History
| <fsssiedxg$"sssiedx | 4.61 | Medium | review | 2026-08-10 |
| <fsssiedx{$'sssiedx | 4.38 | Medium | review | 2026-08-10 |
| <fsssiedxf$"sssiedx | 4.66 | Medium | review | 2026-08-10 |
| %22fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx | 4.62 | Medium | review | 2026-08-10 |
| 'fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx | 4.48 | Medium | review | 2026-08-10 |
| 'fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx | 4.77 | Medium | review | 2026-08-10 |
| "fsssiedxf$"sssiedx | 4.49 | Medium | review | 2026-08-10 |
| fsssiedxf$"sssiedx | 4.62 | Medium | review | 2026-08-10 |
| <fsssiedxa'sssiedx | 4.27 | Medium | review | 2026-08-10 |
| fsssiedx<sssiedx | 4.49 | Medium | block | 2026-08-10 |
| sssieddrubricxsx | 4.34 | Medium | review | 2026-08-09 |
| v3.6</script><script>t73G(9652)</script> | 4.34 | Medium | review | 2026-08-05 |
| <th:t="${dfb}#foreach | 4.70 | Medium | review | 2026-08-05 |
| v3.6&n935620=v982957 | 5.08 | Medium | review | 2026-08-05 |
| v3.6</script><script>9eEb(9175)</script> | 4.44 | Medium | review | 2026-07-29 |
| %76%33%2E%36%39%38%36%37%22%28%29%3B%7D%5D%39%38%35%31 | 4.14 | Medium | review | 2026-07-29 |
| v3.69601/"();}]9849 | 4.21 | Medium | review | 2026-07-29 |
| v3.6"><script>9eEb(9699)</script> | 5.05 | Medium | review | 2026-07-29 |
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%39%65%45%62%28%39%31%36%37%34%29%22 | 4.54 | Medium | review | 2026-07-29 |
| dfb__${98991*97996}__::.x | 4.58 | Medium | review | 2026-07-29 |
| <%={{={@{#{${dfb}}%> | 4.88 | Medium | review | 2026-07-29 |
| dfb[[${98991*97996}]]xca | 4.27 | Medium | review | 2026-07-29 |
| v3.69217523 | 4.32 | Medium | review | 2026-07-29 |
| v3.6 | 4.82 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
433be971077d…
Force block
— not fired
Score recovered
no
Elapsed
38.8s