Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cloud Music Web Player

ghgeanfaiobhckholijgekklghchglgl
Risk Score
5.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 23
Rating 5.0
Last updated 2026-03-24 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer js8231437@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search-provider override silently routes all omnibox queries to chromecrxstore.com while branding itself as 'Google'.
  • Privacy policy is Google's generic account policy — has no scope to this extension; admits data collection and third-party sharing.
  • Developer uses free Gmail account (js8231437@gmail.com); no verified publisher, no business identity.
  • Extension title 'Cloud Music Web Player' is entirely unrelated to its actual function (search hijack) — severe category mismatch.
  • No CSP present; MV3 default CSP applies but no content-script surface area is visible to verify behaviour.

Evidence

  • search_provider_override manifest chrome_settings_overrides.search_provider redirects queries to chromecrxstore.com while labeling itself 'Google' with is_default=true.
  • category_mismatch store Title/description promises cloud music playback; actual function is search-engine hijack to chromecrxstore.com.
  • generic_privacy_policy api Policy URL is Google account-level policy (scope_extension=false, data_collection=true, third_party_sharing=true). Scored +10.0 per v3.5 rule D.
  • free_webmail_developer store Developer email js8231437@gmail.com; no verified publisher, no business domain, no business website.
  • external_host_chromecrxstore.com crx js_external_hosts includes chromecrxstore.com — an unrecognised third-party domain receiving all user search queries.
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; code quality pillar = 0.0.
  • maintenance_3_6mo store months_since_update=6; maintenance pillar +1.5.

Permissions Breakdown

  • chrome_settings_overrides.search_provider (is_default=true) high Silently replaces default search with chromecrxstore.com; name spoofs 'Google' while routing queries to unknown third party.
  • host_permissions: https://suggestqueries.google.com/* medium Used to power spoofed suggest URL; actual suggest endpoint is chromecrxstore.com, not Google.

Pillar Scores

Permissions7.00
Reputation6.50
Network2.00
Webstore5.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 15:51
Listing SHA ae5e6fcbdafa…
Force block — not fired
Score recovered no
Elapsed