Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VUBuddy - VU Firewall Bypass, Lecture Skip, NetAcad & AI Quiz Solver

feooibaaamcllnmdojchjccjljdbdmfb
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 10,000
Rating 4.3
Last updated 2026-05-22 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer gptquizapp@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy on unrelated domain (fmedu.org), admits data collection and 3rd-party sharing without scoping to this extension.
  • Developer is free-webmail Gmail with no verified business name; no recognized-org discounts apply.
  • cookies + scripting on university LMS (vulms.vu.edu.pk) enables session/credential harvesting.
  • install_url_hijack: onInstalled opens internal assets/alert-settings.html — non-standard install redirect pattern.
  • No CSP on MV3 extension; geo-diversity 4 countries (CA, IN, PK, US) with 9 external hosts including tinyurl.com.

Evidence

  • privacy_policy_generic api Policy at fmedu.org: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • free_webmail_no_dev_name store developer_email=gptquizapp@gmail.com, developer_name empty; reputation floor 7.5 applies.
  • cookies_scripting_lms manifest cookies + scripting permissions with host access to vulms.vu.edu.pk; session token theft vector.
  • install_url_hijack crx install_url_hijack=true, target=assets/alert-settings.html (internal page but still anomalous).
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • geo_diversity api 4 countries (CA, IN, PK, US) with 9 external JS hosts including tinyurl.com; +1.5 network.
  • ai_page_content_processing store Extension claims AI Quiz Solver processing page content on LMS; +2.5 webstore AI signal.
  • verified_publisher store verified_publisher=true but dev email is free-webmail; v3.1 0c cap applies, discount capped at -1.0.

Permissions Breakdown

  • storage low Stores user settings locally; low standalone risk.
  • scripting high Can inject scripts into pages; combined with host perms enables broad page manipulation.
  • declarativeNetRequest medium Can block/redirect network requests; used here plausibly for firewall bypass.
  • cookies high Can read/write cookies on permitted domains; risk of session token access on vu.edu.pk.
  • *://vulms.vu.edu.pk/* high Broad host access to university LMS; scripting+cookies here is high-risk for credential/session theft.
  • https://vubuddy.com/* medium Dev-controlled domain; data exfil path cannot be ruled out without code review.

Pillar Scores

Permissions5.50
Reputation7.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA 588bc2c9906c…
Force block — not fired
Score recovered no
Elapsed 26.7s