Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Avatar The Last Airbender New Tab Experience

gghknalafkpohnepehflealomejchcha
Risk Score
5.94
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 287
Rating 3.0
Last updated 2025-04-28 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@gameograf.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — admits data collection & 3rd-party sharing with no extension-specific scope.
  • NewTab override with uninstall URL hijack pointing to gameograf.com UTM tracking endpoint.
  • 9 moderate-severity CVEs across bundled jquery@1.9.1, jquery@3.4.1, jquery-ui@1.12.1 (all XSS); no CSP to mitigate.
  • Install URL hijack on onInstalled; new-tab override pattern with fan-content shell typical of ad-monetization clusters.
  • 16-month stale update with vulnerable JS libraries that are unfixed well past OSV fixed_in versions.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → gameograf.com UTM link; monetization tracking on removal.
  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • newtab_override manifest chrome_url_overrides.newtab=index.html replaces every new tab for all users.
  • cve_moderate_bulk crx 9 moderate CVEs: jquery-ui@1.12.1 (4 XSS), jquery@3.4.1 (2 XSS), jquery@1.9.1 (3 XSS). No CSP present.
  • stale_update store Last updated April 2025 but months_since_update=16; vulnerable libs remain unfixed.
  • fan_content_shell store Avatar fan-theme NewTab with install count 287; matches fan-content/theme shell monetization pattern.
  • no_csp manifest content_security_policy is null on MV3 extension with DOM-manipulation libs carrying XSS CVEs.
  • external_hosts_broad crx 12 JS external hosts including api.whatsapp.com, jqueryui.com, www.crazycraftz.com beyond primary function.

CVE Exposures (9)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.12.1 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2021-41183 jquery-ui@1.12.1 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • search medium Enables reading/manipulating search queries; core to NewTab monetization risk.
  • topSites medium Exposes user's most-visited sites; privacy-sensitive browsing data.
  • unlimitedStorage low Allows unlimited local data storage; low direct harm.
  • storage low Standard key-value storage; low risk.
  • chrome_url_overrides.newtab high Replaces every new tab; prime real estate for tracking, ad injection, search hijacking.

Pillar Scores

Permissions4.00
Reputation5.50
Network3.50
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 12:29
Listing SHA ea2e2340e810…
Force block — not fired
Score recovered no
Elapsed