Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Mouse Tooltip Translator - PDF & Netflix YouTube dual subs

hmigninkgibhdckiaphhmbgcghochdjc
Risk Score
5.61
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 200,000
Rating 4.6
Last updated 2026-08-06
Manifest version MV3
CSP present ✅ yes
Developer ttop324@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358 ACE) + high CVE (CVE-2026-27601 DoS); not patched.
  • Privacy policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — admits broad sharing without extension-specific scope.
  • uninstall_url_hijack=true: extension sets an uninstall URL to a third-party destination.
  • eval() in opencv.js and widespread new Function() across 104 JS files alongside <all_urls> content scripts.
  • Free-webmail developer (ttop324@gmail.com) with brand mention of YouTube/Netflix flagged as impersonation; no verified publisher.

Evidence

  • CVE critical+high in underscore@1.8.3 crx CVE-2021-23358 (ACE, fixed 1.12.1) and CVE-2026-27601 (DoS, fixed 1.13.8); bundled version 1.8.3 unpatched.
  • Privacy policy: collection+third_party_sharing admitted, scope_extension=false api Policy exists on GitHub but does not scope to this extension; admits data collection and third-party sharing.
  • uninstall_url_hijack=true crx chrome.runtime.setUninstallURL() points to a third-party URL; exfil/monetization risk on uninstall.
  • eval + new Function across 20 code findings crx eval() in opencv.js; new Function() in contentScript.js, netflix.js, alert.js and 16 other files.
  • brand_mention impersonation: YouTube, Netflix store is_impersonation=true; confirmed_owner=false; developer domain is gmail.com.
  • Free-webmail developer, no verified publisher store ttop324@gmail.com; verified_publisher=false; featured by Google provides partial trust signal.
  • <all_urls> host_permission + scripting manifest Content scripts inject on all URLs; scripting API enables dynamic injection across every visited page.
  • cdn.jsdelivr.net in js_external_hosts crx Extension references external CDN (jsdelivr.net); CSP allows only 'self', mitigating remote load risk.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Saves user settings locally; standard for translation tools.
  • tts low Text-to-speech output; aligns with translation function.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • scripting high Programmatic script injection into pages; elevated when paired with <all_urls>.
  • contextMenus low Adds right-click menu entries; limited impact.
  • offscreen low Off-screen document for audio/DOM ops; contained scope.
  • search medium Can query default search engine; minor data exposure.
  • <all_urls> (host_permission) high Content scripts run on every site; broad data access surface.

Pillar Scores

Permissions6.10
Reputation6.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00

Scoring History

xx pfsssiedxa$'sssiedx 4.73 Medium block 2026-08-14
'fsssiedxa"sssiedx 5.56 Medium review 2026-08-14
4.73 Medium review 2026-08-14
&#x22;fsssiedxa$'sssiedx 5.48 Medium review 2026-08-14
fsssiedxa$"sssiedx 4.95 Medium review 2026-08-14
<fsssiedxa xx psssiedx 4.59 Medium review 2026-08-13
<fsssiedxa$"sssiedx 4.73 Medium review 2026-08-13
<fsssiedxa"sssiedx 5.18 Medium review 2026-08-13
<fsssiedxa$'sssiedx 4.84 Medium review 2026-08-13
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.73 Medium review 2026-08-13
<fsssiedxa'sssiedx 5.24 Medium review 2026-08-13
fsssiedxa<sssiedx 5.33 Medium review 2026-08-13
sssieddrubricxsx 5.56 Medium review 2026-08-13
v3.6 5.61 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA f75aad21b648…
Force block — not fired
Score recovered no
Elapsed 36.8s