Private video downloader - Telegram Private Video Downloader
gdfhmpjihkjpkcgfoclondnjlignnaap
Risk Score
4.73
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 (Arbitrary Code Execution) in bundled underscore@1.8.3; no CSP amplifies exploit risk.
- Privacy policy admits data collection and third-party sharing without scoping to this extension (generic policy, 508KB).
- Brand impersonation: 'Telegram' mentioned in title/name by unverified free-webmail developer with no business identity.
- Developer uses gmail.com with no developer name; free-webmail + no org identity raises trust concerns.
- Description promises download but 'downloads' permission is absent — permission/function mismatch.
Evidence
- critical_cve_underscore crx underscore@1.8.3 in price.js: CVE-2021-23358 (Arbitrary Code Execution, fixed in 1.12.1). No CSP present.
- generic_privacy_policy store Policy fetched (508KB), scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[telegram]; developer not confirmed owner.
- free_webmail_dev_no_name store developer_email=ericlyle8669@gmail.com; developer_name empty; no business website verified.
- description_permission_mismatch manifest promises 'download' but 'downloads' permission not declared.
- external_host_igtools_ai crx js_external_hosts includes igtools.ai; operator fingerprint ties dev email to this domain.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; caps discount to -1.0 under v3.5 invariant 0c (monetization N/A but CVEs present).
- cve_amplifier_no_csp crx csp_present=false + critical/high CVEs in underscore (DOM-adjacent lib). CVE pillar ×1.5 amplifier applied.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Stores local extension data; minimal risk.
- activeTab low Accesses current tab only on user action; limited scope.
- identity medium Can request OAuth tokens; risk of identity data access.
- https://web.telegram.org/* medium Content script on Telegram web; can read/modify all Telegram page content.
Pillar Scores
Permissions2.30
Reputation7.50
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure6.00
Scoring History
| sssiedn611ca8abdp727562726963xsx | 4.76 | Medium | review | 2026-09-02 |
| xx pfsssiedxa$"sssiedx | 3.56 | Low | review | 2026-08-22 |
| "fsssiedxa$"sssiedx | 5.14 | Medium | review | 2026-08-22 |
| 'fsssiedxasssiedx | 4.41 | Medium | review | 2026-08-22 |
| 4.38 | Medium | review | 2026-08-22 | |
| 'fsssiedxa$'sssiedx | 4.27 | Medium | review | 2026-08-22 |
| "fsssiedxa sssiedx | 5.41 | Medium | review | 2026-08-22 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.12 | Medium | review | 2026-08-22 |
| fsssiedxa<sssiedx | 5.22 | Medium | review | 2026-08-22 |
| fsssiedxa xx psssiedx | 3.33 | Low | block | 2026-08-20 |
| sssieddrubricxsx | 5.32 | Medium | block | 2026-08-20 |
| v3.6 | 4.73 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA
98912f37d061…
Force block
— not fired
Score recovered
no
Elapsed
27.1s