Car Rush
hlmdnedepbbihmbddepemmbkenbnoegd
Risk Score
4.19
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy on CDN (cloudapi.stream) not scoped to this extension, discloses third-party sharing without identifying this extension
- Uninstall URL hijack flag set — extension registers a custom uninstall URL pointing externally
- Install URL hijack: onInstalled redirects to popup/index.html — suspicious open/close pattern
- 7 moderate CVEs across two bundled jQuery versions (2.0.3, 3.2.1), both well below fixed versions
- Free-webmail developer (nadejdinv@gmail.com) with no verified business presence
Evidence
- uninstall_url_hijack crx uninstall_url_hijack=true; target=null — extension sets uninstall URL, destination unresolvable
- install_url_hijack crx install_url_hijack=true; target=popup/index.html — onInstalled opens page, low-grade monetization indicator
- privacy_policy_not_scoped store Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=false, third_party_sharing=true
- free_webmail_developer store Developer email nadejdinv@gmail.com with no verified publisher badge or business domain
- jquery_cve_moderate_x7 crx jquery@2.0.3 (4 CVEs) and jquery@3.2.1 (3 CVEs) all moderate severity, none at fixed_in version
- sandbox_csp_unsafe_eval manifest Sandbox CSP includes unsafe-inline and unsafe-eval; extension_pages CSP is strict
- js_external_hosts_10 crx 10 external JS hosts referenced: bnjmnt4n.now.sh, cloudapi.stream, createjs.com, github.com, goo.gl, etc.
- low_install_game_shell store 170 installs, game category, gmail dev email — classic low-effort game portal shell pattern
CVE Exposures (7)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.0.3 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.0.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.0.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.0.3 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Pillar Scores
Permissions0.00
Reputation7.00
Network0.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:11
Listing SHA
1f027e378143…
Force block
— not fired
Score recovered
no
Elapsed
—