Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Awesome Cookie Manager

hcpidejphgpcgfnpiehkcckkkemgneif
Risk Score
4.53
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category DeveloperTools
Installs 20,000
Rating 4.1
Last updated 2025-08-14 (10 months ago)
Manifest version MV3
CSP present ✅ yes
Developer contact@upway2late.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy (not scoped to this extension) — admits data collection and 3rd-party sharing without extension scope: Privacy pillar maxed.
  • 7 medium-severity CVEs in bundled jquery-ui@1.8.23 (unfixed, version predates all fix points) with eval_user_input in the same library.
  • Brand impersonation: description claims 'Google Chrome cookies' and brand_mention confirms unverified Google brand reference.
  • code_findings confirm eval_user_input + function_constructor + dynamic script creation in bundled libraries alongside <all_urls> + cookies access.
  • No developer name supplied; verified_publisher flag present but privacy policy is a Google generic URL, undermining trust signal.

Evidence

  • privacy_policy_generic_google store Privacy policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • 7x_medium_CVEs_jquery_ui_1.8.23 crx jquery-ui@1.8.23 carries 7 moderate CVEs; all unfixed at bundled version. >=3 medium CVEs → +2.0; +4×0.5 additional unique CVEs → +2.0 cap.
  • eval_user_input_in_jquery_ui crx eval_user_input found in jquery-ui.min.js alongside 7 CVEs and <all_urls>+cookies — high exploitation surface.
  • brand_impersonation_google store brand_mention.is_impersonation=true, brands_mentioned=['google'], confirmed_owner=false, not verified by Google.
  • cookies_plus_all_urls manifest cookies HIGH permission paired with <all_urls> host_permission → ×1.2 multiplier applied; category discount applied for DeveloperTools.
  • no_developer_name store developer_name is empty string; no 'Offered by' name raises identity accountability concern.
  • function_constructor_and_dynamic_script crx function_constructor (+2.5) and script_src_dynamic (+3.0) found in jquery.min.js; code quality elevated.
  • verified_publisher_cap_applied store verified_publisher=true but cve_findings_raw non-empty → v3.5 invariant 0c caps discount to -1.0 on reputation.

CVE Exposures (7)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.8.23 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.8.23 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.8.23 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2016-7103 jquery-ui@1.8.23 moderate 1.12.0 jQuery-UI vulnerable to Cross-site Scripting in dialog closeText
CVE-2021-41183 jquery-ui@1.8.23 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2012-6662 jquery-ui@1.8.23 moderate 1.10.0 jquery-ui Tooltip widget vulnerable to XSS
CVE-2010-5312 jquery-ui@1.8.23 moderate 1.10.0 Cross-site Scripting in jquery-ui

Permissions Breakdown

  • cookies high Full read/write access to all cookies on any site; core to extension function but high sensitivity.
  • <all_urls> (host_permissions) high Broad host access enabling cookie reads across every visited site.
  • tabs medium Can read tab URLs and metadata; moderate privacy risk.
  • activeTab low Limited to user-invoked current tab; lower blast radius.
  • storage low Local extension storage only; no cross-origin risk.

Pillar Scores

Permissions5.70
Reputation6.00
Network0.00
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality7.50
CVE Exposure5.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA 7b2aee80c25d…
Force block — not fired
Score recovered no
Elapsed 39.7s