Video Downloader
fedchalbmgfhdobblebblldiblbmpgdj
Risk Score
4.73
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 (Arbitrary Code Execution); high CVE-2026-27601 also present.
- webRequest + <all_urls> allows full observation of all HTTP traffic across every site.
- Developer is free-webmail Gmail account with no verified business identity.
- Privacy policy hosted on Google Sites; data_collection=true but no retention disclosure.
- DOM-XSS sinks (innerHTML from variable) in contentScript.js and popup.js; CSP present but libs are vulnerable.
Evidence
- cve_critical_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, Arbitrary Code Execution); fixed in 1.12.1. Still bundled.
- cve_high_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
- webrequest_all_urls manifest webRequest + <all_urls> host permission enables passive surveillance of all browser network traffic.
- free_webmail_developer store Developer email is vandathinhadu@gmail.com; no verified business domain; not a verified publisher.
- privacy_policy_google_sites store Policy hosted on Google Sites; scope_extension=true but retention=false and third_party_silence=true.
- dom_xss_sink crx innerHTML from variable in contentScript.js and popup.js; DOM-XSS risk if attacker controls page content.
- is_featured_by_google store Extension carries Google Featured badge, partially offsetting unverified developer reputation.
- js_external_hosts crx lodash.com, openjsf.org, reactjs.org, underscorejs.org listed as JS hosts; no bad-host hits detected.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Local state only; no cross-site risk.
- activeTab low Scoped to user-initiated tab; acceptable for downloader.
- downloads medium Can save arbitrary files to disk; expected for video downloader.
- webRequest high Observes all network requests across all URLs; high surveillance capability.
- <all_urls> (host_permission) high Grants content script and webRequest access to every site the user visits.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore2.00
Maintenance1.50
Privacy2.00
Code Quality4.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:51
Listing SHA
52eb1212048a…
Force block
— not fired
Score recovered
no
Elapsed
—