Perplexity - AI Companion
hlgbcneanomplepojfcnclggenpcoldo
Risk Score
5.87
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; unfixed for 32 months.
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- Extension last updated October 2023 (32 months stale); no active maintenance despite 400K installs.
- Dynamic script creation and new Function() constructor present with no CSP; code execution surface amplified by CVEs.
- 10 external JS hosts resolved (GitHub, CSS theme sites) — exceeds expected surface for a focused AI companion.
Evidence
- critical_cve_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed in 1.12.1 — still at vulnerable version.
- high_cve_underscore crx underscore@1.8.3 also affected by CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
- privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not Perplexity's; scope_extension=false, admits 3rd-party sharing.
- stale_extension store Last updated Oct 2023; 32 months since update with 400K installs and active CVEs.
- no_csp crx content_security_policy is null; MV3 provides some default but no explicit CSP hardening while CVEs present.
- dynamic_script_and_function_constructor crx script_src_dynamic + function_constructor in runtime.js/8558.js — code execution patterns without CSP mitigation.
- 10_external_js_hosts crx js_external_hosts includes 10 domains (GitHub, CSS theme sites); >3 distinct registrable domains.
- verified_publisher_confirmed_owner store verified_publisher=true, brand_mention.confirmed_owner=true, developer domain perplexity.ai resolves. Limits reputation risk.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab medium Grants access to current tab on user action; limited scope but enables page content reads.
- scripting medium Can inject JS/CSS into pages; combined with activeTab enables content extraction.
- https://www.perplexity.ai/ low Scoped host permission to developer's own domain only.
- wss://www.perplexity.ai/ low WebSocket to dev-owned domain; expected for AI query streaming.
Pillar Scores
Permissions2.00
Reputation2.00
Network2.50
Webstore3.50
Maintenance8.50
Privacy10.00
Code Quality5.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
0ee0f10d6519…
Force block
— not fired
Score recovered
no
Elapsed
29.9s