The Read Time: Speed Reading & Listening Software
hieogbibhnhplofpndgbfficihlgahfa
Risk Score
4.73
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- firebasestorage.googleapis.com flagged by URLHaus as malware_download host (AsyncRAT/rev-base64-loader); extension contacts it.
- Dynamic <script> injection in epub-reader.js allows remote code execution against any visited page.
- Broad content_scripts on all http/https URLs combined with new Function() and innerHTML sinks creates XSS surface.
- Privacy policy URL unreachable (fetch_error); cannot verify data handling commitments.
- Install URL hijack opens thereadtime.com/new-installation/ on install; uninstall sends to Google Form feedback collector.
Evidence
- known-bad-host crx firebasestorage.googleapis.com in js_external_hosts matches URLHaus malware_download entry for AsyncRAT/rev-base64-loader.
- script_src_dynamic crx epub-reader.js dynamically creates <script src=e> — arbitrary remote script loading at runtime.
- function_constructor crx pdf-reader.js uses new Function() constructor; code-exec risk.
- broad_host_access manifest content_scripts_matches: http://*/* and https://*/* — runs on every page user visits.
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (ConnectionError); policy content unverifiable.
- install_url_hijack crx onInstalled opens https://thereadtime.com/new-installation/; uninstall URL goes to forms.gle survey.
- verified_publisher_featured store Extension is verified publisher and featured by Google; reputation floor applied at 2.0.
- 12_external_js_hosts crx 12 distinct external JS hosts including github.com, medium.com, us-central1-thereadtimetts.cloudfunctions.net.
CVE Exposures (1)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| firebasestorage.googleapis.com | firebasestorage.googleapis.com | high | — | [urlhaus/malware_download] URLHaus malware_download: ascii,AsyncRAT,rev-base64-l |
Permissions Breakdown
- contextMenus low Adds right-click menu items; low standalone risk.
- activeTab low Accesses current tab on user gesture only.
- storage low Local preference storage; no exfil path alone.
- system.display low Read display info; unusual for reader but low impact.
- alarms low Scheduling only; no data access.
- http://*/* high Broad host access to all HTTP sites via content scripts.
- https://*/* high Broad host access to all HTTPS sites via content scripts.
Pillar Scores
Permissions4.50
Reputation2.00
Network4.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality7.50
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA
2aa2d4b67dbf…
Force block
— not fired
Score recovered
no
Elapsed
30.6s