Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dark Theme - Dark mode for Chrome

gjjbmfigjpgnehjioicaalopaikcnheo
Risk Score
4.02
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Accessibility
Installs 400,000
Rating 4.3
Last updated 2025-11-18 (9 months ago)
Manifest version MV3
CSP present ✅ yes
Developer trankivaterlinh@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); library not updated to fixed version.
  • High CVE also in underscore@1.8.3 (CVE-2026-27601: DoS via unlimited recursion); two unfixed vulns in same lib.
  • scripting + <all_urls> host permission enables script injection on every site the user visits.
  • Developer is anonymous (gmail, no listed name); verified publisher badge partially mitigates but accountability is limited.
  • Privacy policy lacks data retention disclosure and third-party sharing status is unconfirmed (third_party_silence=true).

Evidence

  • critical_cve_in_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed in 1.12.1 — current version not patched.
  • high_cve_in_bundled_lib crx underscore@1.8.3 also carries CVE-2026-27601 (high, DoS); fixed in 1.13.8 — not patched.
  • broad_host_permission_with_scripting manifest <all_urls> + scripting on MV3 allows arbitrary JS injection into every page the user visits.
  • dom_xss_sink crx innerHTML assignment from variable in popup.js; CSP present (self-only) limits but does not eliminate DOM-XSS risk.
  • anonymous_developer store developer_name is empty; email is free Gmail. Verified publisher badge reduces concern but accountability gap remains.
  • privacy_policy_gaps api Policy fetched, scoped, data_collection=true, but retention=false and third_party_silence=true; incomplete disclosure.
  • justified_broad_permission_discount_applied manifest Category=Accessibility; broad host access matches dark-mode function — -1.5 discount applied to permissions pillar.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; standard discounts applied, capped at -1.0 per v3.5(E) due to data_collection.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Stores user theme preferences; minimal risk.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • alarms low Schedules timed events; low standalone risk.
  • scripting high Injects scripts into pages; combined with <all_urls> is high-risk.
  • <all_urls> high Grants script injection and data access on every site the user visits.

Pillar Scores

Permissions5.50
Reputation5.50
Network0.00
Webstore1.00
Maintenance1.50
Privacy2.00
Code Quality2.50
CVE Exposure7.00

Scoring History

sssieddrubricxsx 4.32 Medium review 2026-08-13
v3.6 4.02 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 5db55b1e663f…
Force block — not fired
Score recovered no
Elapsed 28.2s