Mouse Tooltip Translator - PDF & Netflix YouTube dual subs
hmigninkgibhdckiaphhmbgcghochdjc
Risk Score
5.61
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358 ACE) + high CVE (CVE-2026-27601 DoS); not patched.
- Privacy policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — admits broad sharing without extension-specific scope.
- uninstall_url_hijack=true: extension sets an uninstall URL to a third-party destination.
- eval() in opencv.js and widespread new Function() across 104 JS files alongside <all_urls> content scripts.
- Free-webmail developer (ttop324@gmail.com) with brand mention of YouTube/Netflix flagged as impersonation; no verified publisher.
Evidence
- CVE critical+high in underscore@1.8.3 crx CVE-2021-23358 (ACE, fixed 1.12.1) and CVE-2026-27601 (DoS, fixed 1.13.8); bundled version 1.8.3 unpatched.
- Privacy policy: collection+third_party_sharing admitted, scope_extension=false api Policy exists on GitHub but does not scope to this extension; admits data collection and third-party sharing.
- uninstall_url_hijack=true crx chrome.runtime.setUninstallURL() points to a third-party URL; exfil/monetization risk on uninstall.
- eval + new Function across 20 code findings crx eval() in opencv.js; new Function() in contentScript.js, netflix.js, alert.js and 16 other files.
- brand_mention impersonation: YouTube, Netflix store is_impersonation=true; confirmed_owner=false; developer domain is gmail.com.
- Free-webmail developer, no verified publisher store ttop324@gmail.com; verified_publisher=false; featured by Google provides partial trust signal.
- <all_urls> host_permission + scripting manifest Content scripts inject on all URLs; scripting API enables dynamic injection across every visited page.
- cdn.jsdelivr.net in js_external_hosts crx Extension references external CDN (jsdelivr.net); CSP allows only 'self', mitigating remote load risk.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Saves user settings locally; standard for translation tools.
- tts low Text-to-speech output; aligns with translation function.
- tabs medium Can read tab URLs and titles across all open tabs.
- scripting high Programmatic script injection into pages; elevated when paired with <all_urls>.
- contextMenus low Adds right-click menu entries; limited impact.
- offscreen low Off-screen document for audio/DOM ops; contained scope.
- search medium Can query default search engine; minor data exposure.
- <all_urls> (host_permission) high Content scripts run on every site; broad data access surface.
Pillar Scores
Permissions6.10
Reputation6.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00
Scoring History
| xx pfsssiedxa$'sssiedx | 4.73 | Medium | block | 2026-08-14 |
| 'fsssiedxa"sssiedx | 5.56 | Medium | review | 2026-08-14 |
| 4.73 | Medium | review | 2026-08-14 | |
| "fsssiedxa$'sssiedx | 5.48 | Medium | review | 2026-08-14 |
| fsssiedxa$"sssiedx | 4.95 | Medium | review | 2026-08-14 |
| <fsssiedxa xx psssiedx | 4.59 | Medium | review | 2026-08-13 |
| <fsssiedxa$"sssiedx | 4.73 | Medium | review | 2026-08-13 |
| <fsssiedxa"sssiedx | 5.18 | Medium | review | 2026-08-13 |
| <fsssiedxa$'sssiedx | 4.84 | Medium | review | 2026-08-13 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.73 | Medium | review | 2026-08-13 |
| <fsssiedxa'sssiedx | 5.24 | Medium | review | 2026-08-13 |
| fsssiedxa<sssiedx | 5.33 | Medium | review | 2026-08-13 |
| sssieddrubricxsx | 5.56 | Medium | review | 2026-08-13 |
| v3.6 | 5.61 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
f75aad21b648…
Force block
— not fired
Score recovered
no
Elapsed
36.8s