Nissan GTR Live Wallpaper - New Tab Theme
hldbegbdgkebmhbcejncejoihpibjbhp
Risk Score
3.67
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Uninstall and install URL hijack both active — redirects users to gameograf.com on install/uninstall.
- NewTab override replaces every new tab; primary monetization/data surface.
- Two innerHTML DOM-XSS sinks with no CSP; potential XSS if API response is attacker-controlled.
- No developer name listed; verified publisher badge but empty 'Offered by' field.
- search permission combined with NewTab override allows query interception.
Evidence
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL to gameograf.com with UTM tracking params.
- install_url_hijack manifest onInstalled opens gameograf.com with UTM tracking params.
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html; replaces every new tab.
- dom_xss_sink crx innerHTML assignments in popup.js and calendar.js with no CSP guard; DOM-XSS risk.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- verified_publisher store verified_publisher=true for support@gameograf.com; developer_name field is empty.
- privacy_policy api Policy fetched, scoped to extension, discloses data collection, retention, and third-party sharing.
- low_installs store Only 71 installs; very low reach limits blast radius.
Permissions Breakdown
- search medium Allows reading and manipulating search queries; medium risk for a NewTab theme.
- host_permission: https://api.gameograf.com/* low Scoped to own API domain only; low risk.
- chrome_url_overrides.newtab medium Replaces new tab page; core monetization/data-collection surface for NewTab shells.
Pillar Scores
Permissions3.00
Reputation4.00
Network2.50
Webstore7.50
Maintenance1.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:16
Listing SHA
9ef52c3f79fb…
Force block
— not fired
Score recovered
no
Elapsed
—