Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

iCloud Bookmarks

fkepacicchenbjecpbpbclokcabebhah
Risk Score
4.78
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 6,000,000
Rating 3.4
Last updated 2023-11-10 (33 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@apple.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • nativeMessaging to local OS app creates high-capability channel; mitigated by recognized publisher check but unverified_publisher flag is set.
  • Extension last updated 31 months ago (Nov 2023) — stale for a 7M-install extension; no security patches applied in that window.
  • Privacy policy is Apple's generic corporate policy, not scoped to this extension; data collection admitted without extension-specific retention disclosure.
  • No CSP declared (MV3 so no +2 penalty, but combined with nativeMessaging raises residual risk).
  • Operator cluster shows 1 sibling extension under same fingerprint — low concern but noted.

Evidence

  • nativeMessaging + publisher_recognized crx nativeMessaging declared; native_messaging_check.publisher_recognized=true, mitigating +3.0 Permissions penalty.
  • maintenance_stale store Last updated Nov 2023, 31 months ago. Pillar score +8.5 (24-36mo band).
  • privacy_policy_generic store Apple corporate privacy policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=false → +9.0 Privacy.
  • developer_identity store Developer is Apple Inc. (apple.com resolves, not throwaway). verified_publisher=false, not featured.
  • operator_cluster api sibling_count=1 under support@apple.com fingerprint (iCloud Passwords sibling). +2.5 Webstore.
  • installs_reach store 7,000,000 installs → +1.0 (>1M) + +1.0 (>100K) + +1.0 (>10K) Webstore; -0.5 popularity-trust not applied (rating 3.4 < 4.0).
  • code_quality_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty. Code Quality = 0.0.
  • cve_none crx cve_findings_raw empty. CVE pillar = 0.0.

Permissions Breakdown

  • bookmarks medium Read/write access to all bookmarks; core to stated function.
  • nativeMessaging high Allows communication with native app on host OS; broad OS-level channel. Publisher recognized per native_messaging_check.
  • storage low Local extension storage only; low-risk data persistence.

Pillar Scores

Permissions5.50
Reputation2.00
Network2.00
Webstore3.50
Maintenance8.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Operator Siblings (1)

Other extensions sharing this developer's compound fingerprint:

Scoring History

%76%33%2E%36%39%31%30%32%22%28%29%3B%7D%5D%39%37%30%31 4.70 Medium review 2026-08-05
<%={{={@{#{${dfb}}%> 4.29 Medium review 2026-08-05
bfgx3609%C0%BEz1%C0%BCz2a%90bcxhjl3609 4.87 Medium review 2026-08-05
v3.6&n941205=v900834 4.62 Medium review 2026-08-05
v3.6</script><script>OTfY(9374)</script> 4.74 Medium review 2026-07-29
v3.69104"();}]9398 4.64 Medium review 2026-07-29
v3.6"><script>OTfY(9537)</script> 4.82 Medium review 2026-07-29
v3.6" eFZl=OTfY([!+!]) vOs=" 4.82 Medium review 2026-07-29
v3.6"onmouseover=OTfY(90202)" 4.85 Medium review 2026-07-29
dfb{{98991*97996}}xca 5.04 Medium review 2026-07-29
bfgx1508%C0%BEz1%C0%BCz2a%90bcxhjl1508 4.77 Medium review 2026-07-29
bfg7496<s1﹥s2ʺs3ʹhjl7496 4.53 Medium review 2026-07-29
v3.69776069 4.43 Medium review 2026-07-29
'"()&%<zzz><ScRiPt >OTfY(9982)</ScRiPt> 4.14 Medium review 2026-07-29
sssieddrubricxsx 4.37 Medium review 2026-07-28
v3.6 4.78 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA edd0305e9e0b…
Force block — not fired
Score recovered no
Elapsed 21.8s