Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Romantic Valentine's Day: Hearts, Roses, and Love Wallpaper

glfomebddkdcndojnhoalkjohbaphiaf
Risk Score
3.90
Risk Level: Low
Recommendation: 🚫 BLOCK
Category NewTab
Installs 251
Rating
Last updated 2026-05-06 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@ovkas.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijacks to gameograf.com—classic monetization shell uninstall redirect.
  • Privacy policy is Google's own generic policy; not scoped to this extension at all (+10 privacy).
  • NewTab override with search permission = persistent ad-monetization surface on every new tab.
  • Three medium-severity jQuery XSS CVEs (v1.9.1); no CSP present on MV3 extension.
  • No developer name listed; gameograf.com redirect signals affiliate/monetization operator.

Evidence

  • uninstall_url_hijack manifest setUninstallURL targets gameograf.com with UTM params tracking ovkas operator—monetization shell signal.
  • newtab_override manifest chrome_url_overrides.newtab=index.html replaces every new tab; paired with search permission.
  • privacy_policy_generic store Privacy policy URL is myaccount.google.com/privacypolicy—Google's own policy, not scoped to extension.
  • cve_jquery_xss crx jquery@1.9.1 bundled with 3 medium CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in 3.5.0.
  • no_csp manifest content_security_policy is null; no CSP despite bundled vulnerable jQuery.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • install_url_opens_index manifest install_url_hijack true but target is index.html (internal); low additional risk.
  • js_external_hosts_12 crx 12 external JS hosts including gameograf.com, jqueryui.com, crazycraftz.com—broad third-party surface.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • search medium Access to search API; paired with newtab override enables search monetization.
  • topSites medium Reads user's most visited sites; privacy-sensitive browsing data.
  • unlimitedStorage low No direct data exfil risk but enables persistent local data accumulation.
  • storage low Standard local storage; low standalone risk.
  • chrome_url_overrides.newtab medium Replaces every new tab page; high-reach persistent monetization surface.

Pillar Scores

Permissions4.00
Reputation6.00
Network4.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:55
Listing SHA 93ec76c63ead…
Force block — not fired
Score recovered no
Elapsed