Synchro: Productivity Manager for Students
gcfbppmhmopmakhclakgnlpobjedkjhe
Risk Score
5.03
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- 8 moderate CVEs in bundled jquery@1.12.4 and jquery-ui@1.12.1 (all unfixed); XSS risk amplified by absent CSP.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- new Function() constructor in clickout-event.js enables arbitrary code execution from attacker-controlled input.
- Broad host permissions (*.com / *.edu) paired with DOM-XSS sinks and no CSP increases exploitation blast radius.
- Developer is gmail-only with no verified identity; no update timestamp available to assess staleness.
Evidence
- 8 moderate CVEs in jquery@1.12.4 and jquery-ui@1.12.1; none at fixed_in version crx jquery@1.12.4 has CVE-2015-9251/2019-11358/2020-11022/2020-11023; jquery-ui@1.12.1 has CVE-2021-41182/83/84 and CVE-2022-31160.
- No CSP present (MV3 extension with csp_present=false) manifest content_security_policy is null; amplifies XSS risk from vulnerable jquery libs and innerHTML sink.
- function_constructor in clickout-event.js crx new Function(e[1]) called with external data — arbitrary code execution vector.
- Privacy policy is Google generic account policy store URL points to myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- Gmail developer, no verified publisher, no business domain store developer_email=ranashreyas@gmail.com; verified_publisher=false; brand_mention.developer_domain=gmail.com.
- Broad host permissions beyond stated task-tracker function manifest host_permissions include https://*.com/ and https://*.edu/ — wider than needed for local task management.
- last_updated missing; maintenance risk unknown api last_updated is empty string; months_since_update null. Maintenance pillar scored conservatively at 6-12mo band.
- is_featured_by_google=true provides minor trust signal store Google Featured badge reduces reputation risk but does not offset CVE and code-quality findings.
CVE Exposures (8)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.12.1 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2021-41183 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2019-11358 | jquery@1.12.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.12.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Local data persistence; no cross-origin exfil risk on its own.
- notifications low Can show desktop alerts; limited abuse surface.
- https://*.com/ medium Broad host access across all .com sites; wider than needed for a task tracker.
- https://*.edu/ medium Access to all .edu sites; plausible for student tool but still broad.
Pillar Scores
Permissions2.30
Reputation6.50
Network2.00
Webstore1.00
Maintenance5.00
Privacy10.00
Code Quality5.50
CVE Exposure5.25
Scoring History
| v3.6 | 5.03 | Medium | review | 2026-06-16 |
| v3.4-rev | 5.32 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA
8232c7b8b763…
Force block
— not fired
Score recovered
no
Elapsed
38.0s