Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Okta Browser Plugin

glnpjglilkicbckjpbgcfkogebgllemb
Risk Score
4.41
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 4,000,000
Rating 4.3
Last updated 2026-09-02
Manifest version MV3
CSP present ✅ yes
Developer support@okta.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed (SSLError): policy adequacy unverifiable; scored as missing — highest privacy risk.
  • Broad host access (https://*/, http://*/) combined with cookies+scripting+webRequest enables full session/credential access on any site.
  • 5 new Function() constructor calls across background, shared, settings, newtab, and popover scripts — dynamic code execution surface.
  • No developer name listed and unverified publisher for a high-privilege SSO extension with 5M installs.
  • Uninstall and install URL hijack flags set; even with null targets this is an anomalous signal for an enterprise auth plugin.

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL returned SSLError on fetch; classified as fetched=false → pillar scored at 10.0 (no policy).
  • broad_host_permissions manifest https://*/ and http://*/ grant access to every site; paired with cookies, scripting, webRequest.
  • multiple_function_constructor crx 5 distinct new Function() calls in background.js, shared.js, newtab, settings-page, popover — dynamic eval surface.
  • dom_xss_sink crx innerHTML assigned from variable in shared.js without apparent sanitization — DOM-XSS risk.
  • no_developer_name store developer_name is empty string; verified_publisher=false for 5M-install enterprise SSO extension.
  • install_uninstall_url_hijack manifest uninstall_url_hijack=true and install_url_hijack=true; targets null but flags are set.
  • pendo_analytics_host crx app.pendo.io and data.pendo.io in js_external_hosts — third-party analytics touching enterprise SSO flows.
  • no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.

Permissions Breakdown

  • tabs medium Allows reading tab URLs/titles across all sites — necessary for SSO redirect detection.
  • cookies high Can read/write cookies on all HTTPS/HTTP origins; paired with broad host access — critical surface.
  • storage low Local extension storage; low risk on its own.
  • unlimitedStorage low Allows larger storage quota; low additional risk.
  • webRequest high Intercepts all HTTP/HTTPS requests across all sites; core SSO intercept capability.
  • webNavigation medium Tracks navigation events across all tabs; needed for SSO flow detection.
  • scripting high Can inject scripts into any page; broad host access makes this very high capability.
  • declarativeNetRequestWithHostAccess high Can block/modify network requests on all hosts; powerful request manipulation.
  • webRequestAuthProvider high Can handle HTTP auth challenges; allows credential interception surface.
  • https://*/ high Broad host access over all HTTPS origins; combined with cookies/scripting is critical reach.
  • http://*/ high Broad host access over all HTTP origins; extends capability to non-TLS sites.

Pillar Scores

Permissions5.50
Reputation4.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Scoring History

sssiedn0351b020dp727562726963xsx 4.74 Medium review 2026-09-09
v3.6 4.41 Medium review 2026-08-27

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 09:34
Listing SHA 583014f9ab6c…
Force block — not fired
Score recovered no
Elapsed