Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Downloader

fedchalbmgfhdobblebblldiblbmpgdj
Risk Score
4.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 60,000
Rating 3.9
Last updated 2026-04-12 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer vandathinhadu@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (Arbitrary Code Execution); high CVE-2026-27601 also present.
  • webRequest + <all_urls> allows full observation of all HTTP traffic across every site.
  • Developer is free-webmail Gmail account with no verified business identity.
  • Privacy policy hosted on Google Sites; data_collection=true but no retention disclosure.
  • DOM-XSS sinks (innerHTML from variable) in contentScript.js and popup.js; CSP present but libs are vulnerable.

Evidence

  • cve_critical_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, Arbitrary Code Execution); fixed in 1.12.1. Still bundled.
  • cve_high_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
  • webrequest_all_urls manifest webRequest + <all_urls> host permission enables passive surveillance of all browser network traffic.
  • free_webmail_developer store Developer email is vandathinhadu@gmail.com; no verified business domain; not a verified publisher.
  • privacy_policy_google_sites store Policy hosted on Google Sites; scope_extension=true but retention=false and third_party_silence=true.
  • dom_xss_sink crx innerHTML from variable in contentScript.js and popup.js; DOM-XSS risk if attacker controls page content.
  • is_featured_by_google store Extension carries Google Featured badge, partially offsetting unverified developer reputation.
  • js_external_hosts crx lodash.com, openjsf.org, reactjs.org, underscorejs.org listed as JS hosts; no bad-host hits detected.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Local state only; no cross-site risk.
  • activeTab low Scoped to user-initiated tab; acceptable for downloader.
  • downloads medium Can save arbitrary files to disk; expected for video downloader.
  • webRequest high Observes all network requests across all URLs; high surveillance capability.
  • <all_urls> (host_permission) high Grants content script and webRequest access to every site the user visits.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore2.00
Maintenance1.50
Privacy2.00
Code Quality4.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:51
Listing SHA 52eb1212048a…
Force block — not fired
Score recovered no
Elapsed