Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Ad Blocker Plus

hegneaniplmfjcmohoclabblbahcbjoe
Risk Score
4.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Adblock
Installs 50,000
Rating 3.9
Last updated 2026-05-18 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer orsonkent184@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; unfixed version deployed.
  • High CVE-2026-27601 in same underscore lib; no CSP amplifies DOM-manipulation risk from vulnerable lib.
  • new Function() constructor in service_worker.js paired with broad host access is a high-risk capability combo.
  • innerHTML sinks in content.js/popup.js/welcome.js with no CSP create DOM-XSS attack surface across all sites.
  • Free-webmail dev (gmail), no developer name, verified_publisher claim without matched domain raises identity risk.

Evidence

  • CVE-critical-underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code exec); fixed_in 1.12.1 not applied.
  • CVE-high-underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8 not applied.
  • no-CSP-amplifies-CVE crx csp_present==false with underscore (DOM-manip lib) having high/critical CVEs; CVE pillar ×1.5 amplifier applied.
  • function_constructor crx new Function() in service_worker.js; combined with broad host_permissions this is a high-risk capability.
  • innerHTML-sinks-no-csp crx dom_sink_innerhtml_userctrl in 3 files; csp_present==false triggers +2.0 code-quality penalty each.
  • free-webmail-dev-no-name store developer_email is gmail.com, developer_name empty; verified_publisher flagged but domain identity unconfirmed.
  • broad-host-webRequest manifest webRequest + *://*/* covers all sites; justified-broad discount applied for Adblock category but residual HIGH remains.
  • google-analytics-telemetry crx js_external_hosts includes www.google-analytics.com; monetization_hits telemetry tier only.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Access to tab URLs/titles; moderate risk for an adblocker.
  • webNavigation medium Monitors navigation events; needed for ad-blocking logic.
  • webRequest high Can observe all network requests across all URLs; high-impact capability.
  • storage low Local settings persistence; low risk.
  • contextMenus low Adds right-click menu items; low risk.
  • *://*/* high Broad host access paired with webRequest; covers every site the user visits.

Pillar Scores

Permissions5.50
Reputation6.50
Network4.50
Webstore2.50
Maintenance0.00
Privacy0.00
Code Quality5.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:43
Listing SHA eb9a20a6002e…
Force block — not fired
Score recovered no
Elapsed