Video Ad Blocker Plus
hegneaniplmfjcmohoclabblbahcbjoe
Risk Score
4.73
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; unfixed version deployed.
- High CVE-2026-27601 in same underscore lib; no CSP amplifies DOM-manipulation risk from vulnerable lib.
- new Function() constructor in service_worker.js paired with broad host access is a high-risk capability combo.
- innerHTML sinks in content.js/popup.js/welcome.js with no CSP create DOM-XSS attack surface across all sites.
- Free-webmail dev (gmail), no developer name, verified_publisher claim without matched domain raises identity risk.
Evidence
- CVE-critical-underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code exec); fixed_in 1.12.1 not applied.
- CVE-high-underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8 not applied.
- no-CSP-amplifies-CVE crx csp_present==false with underscore (DOM-manip lib) having high/critical CVEs; CVE pillar ×1.5 amplifier applied.
- function_constructor crx new Function() in service_worker.js; combined with broad host_permissions this is a high-risk capability.
- innerHTML-sinks-no-csp crx dom_sink_innerhtml_userctrl in 3 files; csp_present==false triggers +2.0 code-quality penalty each.
- free-webmail-dev-no-name store developer_email is gmail.com, developer_name empty; verified_publisher flagged but domain identity unconfirmed.
- broad-host-webRequest manifest webRequest + *://*/* covers all sites; justified-broad discount applied for Adblock category but residual HIGH remains.
- google-analytics-telemetry crx js_external_hosts includes www.google-analytics.com; monetization_hits telemetry tier only.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- tabs medium Access to tab URLs/titles; moderate risk for an adblocker.
- webNavigation medium Monitors navigation events; needed for ad-blocking logic.
- webRequest high Can observe all network requests across all URLs; high-impact capability.
- storage low Local settings persistence; low risk.
- contextMenus low Adds right-click menu items; low risk.
- *://*/* high Broad host access paired with webRequest; covers every site the user visits.
Pillar Scores
Permissions5.50
Reputation6.50
Network4.50
Webstore2.50
Maintenance0.00
Privacy0.00
Code Quality5.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:43
Listing SHA
eb9a20a6002e…
Force block
— not fired
Score recovered
no
Elapsed
—