Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

The Read Time: Speed Reading & Listening Software

hieogbibhnhplofpndgbfficihlgahfa
Risk Score
4.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category ReaderMode
Installs 4,000
Rating 4.9
Last updated 2026-05-29 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@thereadtime.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • firebasestorage.googleapis.com flagged by URLHaus as malware_download host (AsyncRAT/rev-base64-loader); extension contacts it.
  • Dynamic <script> injection in epub-reader.js allows remote code execution against any visited page.
  • Broad content_scripts on all http/https URLs combined with new Function() and innerHTML sinks creates XSS surface.
  • Privacy policy URL unreachable (fetch_error); cannot verify data handling commitments.
  • Install URL hijack opens thereadtime.com/new-installation/ on install; uninstall sends to Google Form feedback collector.

Evidence

  • known-bad-host crx firebasestorage.googleapis.com in js_external_hosts matches URLHaus malware_download entry for AsyncRAT/rev-base64-loader.
  • script_src_dynamic crx epub-reader.js dynamically creates <script src=e> — arbitrary remote script loading at runtime.
  • function_constructor crx pdf-reader.js uses new Function() constructor; code-exec risk.
  • broad_host_access manifest content_scripts_matches: http://*/* and https://*/* — runs on every page user visits.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (ConnectionError); policy content unverifiable.
  • install_url_hijack crx onInstalled opens https://thereadtime.com/new-installation/; uninstall URL goes to forms.gle survey.
  • verified_publisher_featured store Extension is verified publisher and featured by Google; reputation floor applied at 2.0.
  • 12_external_js_hosts crx 12 distinct external JS hosts including github.com, medium.com, us-central1-thereadtimetts.cloudfunctions.net.

CVE Exposures (1)

CVELibrarySeverity Fixed inSummary
firebasestorage.googleapis.com firebasestorage.googleapis.com high [urlhaus/malware_download] URLHaus malware_download: ascii,AsyncRAT,rev-base64-l

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • activeTab low Accesses current tab on user gesture only.
  • storage low Local preference storage; no exfil path alone.
  • system.display low Read display info; unusual for reader but low impact.
  • alarms low Scheduling only; no data access.
  • http://*/* high Broad host access to all HTTP sites via content scripts.
  • https://*/* high Broad host access to all HTTPS sites via content scripts.

Pillar Scores

Permissions4.50
Reputation2.00
Network4.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality7.50
CVE Exposure5.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA 2aa2d4b67dbf…
Force block — not fired
Score recovered no
Elapsed 30.6s