Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Adobe Acrobat: PDF edit, convert, sign tools

efaidnbmnnnibpcajpcglclefindmkaj
Risk Score
4.82
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 306,000,000
Rating 4.4
Last updated 2026-08-10
Manifest version MV3
CSP present ✅ yes
Developer chrome-support@adobe.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed (timeout); treated as no policy — score 10.0 on privacy pillar.
  • nativeMessaging declared but companion-app publisher not recognized, enabling local system bridge.
  • jquery@3.1.1 bundles 3 moderate CVEs (XSS); fixed versions available (3.4.0/3.5.0) — library not updated.
  • cookies + <all_urls> + webRequest + scripting combination grants broad read/write capability across every site.
  • 6 innerHTML DOM-XSS sinks in content scripts active on <all_urls>; CVEs present amplify XSS surface.

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL present but fetch timed out; classified as fetched=false → pillar scores 10.0.
  • native_messaging_unrecognized_publisher crx nativeMessaging declared; native_messaging_check.publisher_recognized=false.
  • jquery_cve_bundle crx jquery@3.1.1 bundles CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all moderate); fixed_in 3.5.0.
  • broad_host_access_high_perms manifest cookies+webRequest+scripting+<all_urls>; ×1.2 amplifier applied to permissions pillar.
  • dom_xss_sinks crx 6 innerHTML-from-variable findings in content scripts running on <all_urls>; CVEs present → FIX B applies (+2.0).
  • featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied; floor 2.0 enforced.
  • large_install_base store 328M installs; +1.0+1.0+0.5 webstore; -0.5 popularity-trust discount applied.
  • recently_updated store months_since_update=0; maintenance pillar=0.0.

CVE Exposures (1)

CVELibrarySeverity Fixed inSummary
CVE-2025-2792 @mozilla/readability@unknown low 0.6.0 @mozilla/readability Denial of Service through Regex

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • downloads medium Can intercept and manage file downloads.
  • nativeMessaging high Communicates with native Adobe desktop app; publisher_recognized=false raises concern.
  • webRequest high Can observe all HTTP requests across all URLs (paired with <all_urls>).
  • webNavigation medium Tracks navigation events across tabs.
  • storage low Local/sync data storage; minimal standalone risk.
  • scripting high Can inject scripts into any page given <all_urls> host permission.
  • alarms low Schedules background tasks; low risk.
  • offscreen low Creates offscreen documents for background processing.
  • cookies high Can read/write cookies for all sites paired with <all_urls>; ×1.2 amplifier applies.
  • sidePanel low Renders UI in browser side panel.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • fileSystem medium Access to local file system entries.
  • <all_urls> high Broad host access covering every site; amplifies cookies, webRequest, scripting.

Pillar Scores

Permissions7.50
Reputation2.00
Network3.50
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure3.75

Scoring History

<fsssiedxg$"sssiedx 4.61 Medium review 2026-08-10
<fsssiedx{$'sssiedx 4.38 Medium review 2026-08-10
<fsssiedxf$"sssiedx 4.66 Medium review 2026-08-10
%22fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx 4.62 Medium review 2026-08-10
'fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx 4.48 Medium review 2026-08-10
&#x27;fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx 4.77 Medium review 2026-08-10
&#x22;fsssiedxf$"sssiedx 4.49 Medium review 2026-08-10
fsssiedxf$"sssiedx 4.62 Medium review 2026-08-10
<fsssiedxa&#x27;sssiedx 4.27 Medium review 2026-08-10
fsssiedx<sssiedx 4.49 Medium block 2026-08-10
sssieddrubricxsx 4.34 Medium review 2026-08-09
v3.6</script><script>t73G(9652)</script> 4.34 Medium review 2026-08-05
<th:t="${dfb}#foreach 4.70 Medium review 2026-08-05
v3.6&n935620=v982957 5.08 Medium review 2026-08-05
v3.6</script><script>9eEb(9175)</script> 4.44 Medium review 2026-07-29
%76%33%2E%36%39%38%36%37%22%28%29%3B%7D%5D%39%38%35%31 4.14 Medium review 2026-07-29
v3.69601/"();}]9849 4.21 Medium review 2026-07-29
v3.6"><script>9eEb(9699)</script> 5.05 Medium review 2026-07-29
%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%39%65%45%62%28%39%31%36%37%34%29%22 4.54 Medium review 2026-07-29
dfb__${98991*97996}__::.x 4.58 Medium review 2026-07-29
<%={{={@{#{${dfb}}%> 4.88 Medium review 2026-07-29
dfb[[${98991*97996}]]xca 4.27 Medium review 2026-07-29
v3.69217523 4.32 Medium review 2026-07-29
v3.6 4.82 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 433be971077d…
Force block — not fired
Score recovered no
Elapsed 38.8s