Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Private video downloader - Telegram Private Video Downloader

gdfhmpjihkjpkcgfoclondnjlignnaap
Risk Score
4.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 60,000
Rating 4.7
Last updated 2026-07-28 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer ericlyle8669@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (Arbitrary Code Execution) in bundled underscore@1.8.3; no CSP amplifies exploit risk.
  • Privacy policy admits data collection and third-party sharing without scoping to this extension (generic policy, 508KB).
  • Brand impersonation: 'Telegram' mentioned in title/name by unverified free-webmail developer with no business identity.
  • Developer uses gmail.com with no developer name; free-webmail + no org identity raises trust concerns.
  • Description promises download but 'downloads' permission is absent — permission/function mismatch.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 in price.js: CVE-2021-23358 (Arbitrary Code Execution, fixed in 1.12.1). No CSP present.
  • generic_privacy_policy store Policy fetched (508KB), scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[telegram]; developer not confirmed owner.
  • free_webmail_dev_no_name store developer_email=ericlyle8669@gmail.com; developer_name empty; no business website verified.
  • description_permission_mismatch manifest promises 'download' but 'downloads' permission not declared.
  • external_host_igtools_ai crx js_external_hosts includes igtools.ai; operator fingerprint ties dev email to this domain.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; caps discount to -1.0 under v3.5 invariant 0c (monetization N/A but CVEs present).
  • cve_amplifier_no_csp crx csp_present=false + critical/high CVEs in underscore (DOM-adjacent lib). CVE pillar ×1.5 amplifier applied.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Stores local extension data; minimal risk.
  • activeTab low Accesses current tab only on user action; limited scope.
  • identity medium Can request OAuth tokens; risk of identity data access.
  • https://web.telegram.org/* medium Content script on Telegram web; can read/modify all Telegram page content.

Pillar Scores

Permissions2.30
Reputation7.50
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure6.00

Scoring History

sssiedn611ca8abdp727562726963xsx 4.76 Medium review 2026-09-02
xx pfsssiedxa$"sssiedx 3.56 Low review 2026-08-22
"fsssiedxa$"sssiedx 5.14 Medium review 2026-08-22
'fsssiedxasssiedx 4.41 Medium review 2026-08-22
4.38 Medium review 2026-08-22
'fsssiedxa$'sssiedx 4.27 Medium review 2026-08-22
"fsssiedxa sssiedx 5.41 Medium review 2026-08-22
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.12 Medium review 2026-08-22
fsssiedxa<sssiedx 5.22 Medium review 2026-08-22
fsssiedxa xx psssiedx 3.33 Low block 2026-08-20
sssieddrubricxsx 5.32 Medium block 2026-08-20
v3.6 4.73 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 98912f37d061…
Force block — not fired
Score recovered no
Elapsed 27.1s