Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screenshot Capture

giabbpobpebjfegnpcclkocepcgockkc
Risk Score
5.04
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 100,000
Rating 4.1
Last updated 2023-11-21 (31 months ago)
Manifest version MV3
CSP present ❌ no
Developer simov@outofindex.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Extension has not been updated in ~31 months; bundled jquery@3.1.1 has 3 unpatched medium CVEs (XSS).
  • No CSP present combined with vulnerable jQuery (DOM-manipulation lib) triggers CVE amplifier (×1.5 on CVE pillar).
  • Description promises 'recording' capability but lacks tabCapture/desktopCapture — description/permission mismatch.
  • 31-month staleness with multiple CVEs and Google generic privacy policy indicates governance neglect.

Evidence

  • jquery@3.1.1 bundled — 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), fixed in 3.5.0 crx vendor/jquery.min.js version 3.1.1 is below all fixed_in thresholds; no update since Nov 2023.
  • No CSP present — MV3 strict default applies, but CVE amplifier ×1.5 triggered (no CSP + medium CVE in DOM-manip lib) manifest content_security_policy is null; jquery is a DOM-manipulation lib matching the amplifier condition.
  • Privacy policy is Google's generic account policy, not scoped to this extension store scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy pillar (v3.5 rule D).
  • 31 months since last update — maintenance score 8.5 store Last updated November 21, 2023; falls in 24–36 month band.
  • Description/permission mismatch: promises recording but lacks tabCapture/desktopCapture store description_promise.mismatches non-empty; is_shell_pattern=false.
  • Featured by Google badge present — applied -2.0 Reputation discount store is_featured_by_google=true; no verified_publisher badge.
  • No bad-host, affiliate, or monetization hits in threat_intel crx bad_host_hits, affiliate_hits, monetization_hits all empty.
  • Operator cluster sibling_count=0; single-extension fingerprint, no cluster risk api compound sibling_count=0; dev_email sibling_count=0.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Stores user settings/preferences locally; low impact.
  • scripting medium Allows injecting scripts into pages; scoped to activeTab so moderate risk.
  • activeTab low Grants access to current tab on user action only; transient, low risk.

Pillar Scores

Permissions1.60
Reputation4.50
Network0.00
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality3.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 6a24185ed8bc…
Force block — not fired
Score recovered no
Elapsed 27.6s