Dark Theme - Dark mode for Chrome
gjjbmfigjpgnehjioicaalopaikcnheo
Risk Score
4.02
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); library not updated to fixed version.
- High CVE also in underscore@1.8.3 (CVE-2026-27601: DoS via unlimited recursion); two unfixed vulns in same lib.
- scripting + <all_urls> host permission enables script injection on every site the user visits.
- Developer is anonymous (gmail, no listed name); verified publisher badge partially mitigates but accountability is limited.
- Privacy policy lacks data retention disclosure and third-party sharing status is unconfirmed (third_party_silence=true).
Evidence
- critical_cve_in_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed in 1.12.1 — current version not patched.
- high_cve_in_bundled_lib crx underscore@1.8.3 also carries CVE-2026-27601 (high, DoS); fixed in 1.13.8 — not patched.
- broad_host_permission_with_scripting manifest <all_urls> + scripting on MV3 allows arbitrary JS injection into every page the user visits.
- dom_xss_sink crx innerHTML assignment from variable in popup.js; CSP present (self-only) limits but does not eliminate DOM-XSS risk.
- anonymous_developer store developer_name is empty; email is free Gmail. Verified publisher badge reduces concern but accountability gap remains.
- privacy_policy_gaps api Policy fetched, scoped, data_collection=true, but retention=false and third_party_silence=true; incomplete disclosure.
- justified_broad_permission_discount_applied manifest Category=Accessibility; broad host access matches dark-mode function — -1.5 discount applied to permissions pillar.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; standard discounts applied, capped at -1.0 per v3.5(E) due to data_collection.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Stores user theme preferences; minimal risk.
- tabs medium Can read tab URLs and titles across all open tabs.
- alarms low Schedules timed events; low standalone risk.
- scripting high Injects scripts into pages; combined with <all_urls> is high-risk.
- <all_urls> high Grants script injection and data access on every site the user visits.
Pillar Scores
Permissions5.50
Reputation5.50
Network0.00
Webstore1.00
Maintenance1.50
Privacy2.00
Code Quality2.50
CVE Exposure7.00
Scoring History
| sssieddrubricxsx | 4.32 | Medium | review | 2026-08-13 |
| v3.6 | 4.02 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA
5db55b1e663f…
Force block
— not fired
Score recovered
no
Elapsed
28.2s