Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Perplexity - AI Companion

hlgbcneanomplepojfcnclggenpcoldo
Risk Score
5.87
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 400,000
Rating 3.8
Last updated 2023-10-12 (32 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@perplexity.ai
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; unfixed for 32 months.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Extension last updated October 2023 (32 months stale); no active maintenance despite 400K installs.
  • Dynamic script creation and new Function() constructor present with no CSP; code execution surface amplified by CVEs.
  • 10 external JS hosts resolved (GitHub, CSS theme sites) — exceeds expected surface for a focused AI companion.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed in 1.12.1 — still at vulnerable version.
  • high_cve_underscore crx underscore@1.8.3 also affected by CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
  • privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not Perplexity's; scope_extension=false, admits 3rd-party sharing.
  • stale_extension store Last updated Oct 2023; 32 months since update with 400K installs and active CVEs.
  • no_csp crx content_security_policy is null; MV3 provides some default but no explicit CSP hardening while CVEs present.
  • dynamic_script_and_function_constructor crx script_src_dynamic + function_constructor in runtime.js/8558.js — code execution patterns without CSP mitigation.
  • 10_external_js_hosts crx js_external_hosts includes 10 domains (GitHub, CSS theme sites); >3 distinct registrable domains.
  • verified_publisher_confirmed_owner store verified_publisher=true, brand_mention.confirmed_owner=true, developer domain perplexity.ai resolves. Limits reputation risk.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • activeTab medium Grants access to current tab on user action; limited scope but enables page content reads.
  • scripting medium Can inject JS/CSS into pages; combined with activeTab enables content extraction.
  • https://www.perplexity.ai/ low Scoped host permission to developer's own domain only.
  • wss://www.perplexity.ai/ low WebSocket to dev-owned domain; expected for AI query streaming.

Pillar Scores

Permissions2.00
Reputation2.00
Network2.50
Webstore3.50
Maintenance8.50
Privacy10.00
Code Quality5.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA 0ee0f10d6519…
Force block — not fired
Score recovered no
Elapsed 29.9s