Avatar The Last Airbender New Tab Experience
gghknalafkpohnepehflealomejchcha
Risk Score
5.94
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — admits data collection & 3rd-party sharing with no extension-specific scope.
- NewTab override with uninstall URL hijack pointing to gameograf.com UTM tracking endpoint.
- 9 moderate-severity CVEs across bundled jquery@1.9.1, jquery@3.4.1, jquery-ui@1.12.1 (all XSS); no CSP to mitigate.
- Install URL hijack on onInstalled; new-tab override pattern with fan-content shell typical of ad-monetization clusters.
- 16-month stale update with vulnerable JS libraries that are unfixed well past OSV fixed_in versions.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → gameograf.com UTM link; monetization tracking on removal.
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- newtab_override manifest chrome_url_overrides.newtab=index.html replaces every new tab for all users.
- cve_moderate_bulk crx 9 moderate CVEs: jquery-ui@1.12.1 (4 XSS), jquery@3.4.1 (2 XSS), jquery@1.9.1 (3 XSS). No CSP present.
- stale_update store Last updated April 2025 but months_since_update=16; vulnerable libs remain unfixed.
- fan_content_shell store Avatar fan-theme NewTab with install count 287; matches fan-content/theme shell monetization pattern.
- no_csp manifest content_security_policy is null on MV3 extension with DOM-manipulation libs carrying XSS CVEs.
- external_hosts_broad crx 12 JS external hosts including api.whatsapp.com, jqueryui.com, www.crazycraftz.com beyond primary function.
CVE Exposures (9)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.12.1 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2021-41183 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- search medium Enables reading/manipulating search queries; core to NewTab monetization risk.
- topSites medium Exposes user's most-visited sites; privacy-sensitive browsing data.
- unlimitedStorage low Allows unlimited local data storage; low direct harm.
- storage low Standard key-value storage; low risk.
- chrome_url_overrides.newtab high Replaces every new tab; prime real estate for tracking, ad injection, search hijacking.
Pillar Scores
Permissions4.00
Reputation5.50
Network3.50
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 12:29
Listing SHA
ea2e2340e810…
Force block
— not fired
Score recovered
no
Elapsed
—