Cloud Music Web Player
ghgeanfaiobhckholijgekklghchglgl
Risk Score
5.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Search-provider override silently routes all omnibox queries to chromecrxstore.com while branding itself as 'Google'.
- Privacy policy is Google's generic account policy — has no scope to this extension; admits data collection and third-party sharing.
- Developer uses free Gmail account (js8231437@gmail.com); no verified publisher, no business identity.
- Extension title 'Cloud Music Web Player' is entirely unrelated to its actual function (search hijack) — severe category mismatch.
- No CSP present; MV3 default CSP applies but no content-script surface area is visible to verify behaviour.
Evidence
- search_provider_override manifest chrome_settings_overrides.search_provider redirects queries to chromecrxstore.com while labeling itself 'Google' with is_default=true.
- category_mismatch store Title/description promises cloud music playback; actual function is search-engine hijack to chromecrxstore.com.
- generic_privacy_policy api Policy URL is Google account-level policy (scope_extension=false, data_collection=true, third_party_sharing=true). Scored +10.0 per v3.5 rule D.
- free_webmail_developer store Developer email js8231437@gmail.com; no verified publisher, no business domain, no business website.
- external_host_chromecrxstore.com crx js_external_hosts includes chromecrxstore.com — an unrecognised third-party domain receiving all user search queries.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; code quality pillar = 0.0.
- maintenance_3_6mo store months_since_update=6; maintenance pillar +1.5.
Permissions Breakdown
- chrome_settings_overrides.search_provider (is_default=true) high Silently replaces default search with chromecrxstore.com; name spoofs 'Google' while routing queries to unknown third party.
- host_permissions: https://suggestqueries.google.com/* medium Used to power spoofed suggest URL; actual suggest endpoint is chromecrxstore.com, not Google.
Pillar Scores
Permissions7.00
Reputation6.50
Network2.00
Webstore5.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 15:51
Listing SHA
ae5e6fcbdafa…
Force block
— not fired
Score recovered
no
Elapsed
—