Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AerateFinder

ggfpkajpmdihdfmdecfdflpmdoaegcpa
Risk Score
6.27
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 3
Rating
Last updated 2026-06-10 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer aeratefinder@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override to oavsrchrdr.com hijacks all user searches through opaque third-party ad-tech domain.
  • Uninstall URL hijack active — extension redirects user on removal to undisclosed third-party URL.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
  • Free-webmail developer with no verified identity, no developer name, and only 3 installs — classic tail-attack surface.
  • webRequest permission combined with broad search redirect enables full surveillance of user queries.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to oavsrchrdr.com with is_default:true; third-party ad redirect domain.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target null but runtime call confirmed; user redirected on removal.
  • privacy_policy_generic_admits_collection api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy.
  • free_webmail_no_dev_name store developer_email=aeratefinder@gmail.com, developer_name empty; no verified business identity.
  • install_perm_anomaly api 3 installs with HIGH-tier webRequest + search override; small_install_high_perm=true.
  • js_external_hosts_mismatch crx JS contacts baking recipe sites (bakefromscratch.com, sallysbakingaddiction.com) unrelated to stated search function.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
  • oavsrchrdr_host_permission manifest Host permission for https://*.oavsrchrdr.com/* — opaque third-party domain integral to search redirect.

Permissions Breakdown

  • storage low Stores extension state locally; low standalone risk.
  • webRequest high Can observe all network requests; enables traffic interception and surveillance.
  • activeTab medium Access to current tab content on user interaction; moderate risk.
  • host:https://*.aeratefinder.com/* medium Dev-owned domain; needed for search/suggest functions.
  • host:https://*.oavsrchrdr.com/* high Third-party redirect domain used as default search; opaque ownership, monetization likely.
  • chrome_settings_overrides.search_provider high Forces oavsrchrdr.com as default search engine; classic search-hijack vector.

Pillar Scores

Permissions7.50
Reputation7.50
Network2.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:38
Listing SHA 30a95c53620c…
Force block — not fired
Score recovered no
Elapsed