Martian Aptos & Sui Wallet Extension
efbglgofoippbgcjepnhiblaibcnclgk
Risk Score
4.38
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 (Arbitrary Code Execution) in bundled underscore@1.8.3; not patched to fixed_in 1.12.1.
- High CVE-2026-27601 in underscore@1.8.3 compounds CVE exposure; cve_pillar=7.0 triggers block threshold.
- Privacy policy fetched but scope_extension==false AND data_collection+third_party_sharing==true → v3.5(D) scores +10 (admits data sharing, unscoped).
- <all_urls> host permission with content scripts on all URLs gives wallet broad page access on every site visited.
- DOM-XSS sink (innerHTML with user-controlled variable) in blocker.js; CSP present but does not eliminate runtime DOM risk.
Evidence
- cve_critical_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Currently bundled version is unpatched.
- cve_high_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
- privacy_policy_unscoped_admits_sharing store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.
- host_permission_all_urls manifest <all_urls> host permission + content_scripts on http://*/* and https://*/* — injected on every page.
- dom_xss_sink crx blocker.js: innerHTML assigned from variable 'n'; DOM-XSS sink with CSP present but not eval-blocking.
- verified_publisher store verified_publisher=true; months_since_update=12 (<18mo), cap not triggered by staleness alone.
- mixpanel_telemetry crx External hosts include api-js.mixpanel.com, cdn.mxpnl.com, mixpanel.com — telemetry/analytics endpoints.
- maintenance_6_12mo store months_since_update=12; falls in 6-12mo band → +3.5 maintenance score.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- tabs medium Can read tab URLs and titles; relevant for wallet dApp detection but elevated.
- storage low Stores wallet state locally; standard for a crypto wallet extension.
- notifications low Transaction/status alerts; expected for wallet UX.
- <all_urls> (host_permission) high Content scripts injected on every page via content_scripts_matches; broad reach for wallet injection.
Pillar Scores
Permissions5.00
Reputation2.50
Network2.50
Webstore2.00
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
9c67c274f313…
Force block
— not fired
Score recovered
no
Elapsed
42.6s