Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tab Session Manager

iaiomicjabeggjcfkbimgmglanimpnae
Risk Score
4.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 3.5
Last updated 2026-02-24 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer sienori.firefox+c@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 allows arbitrary code execution; unfixed (fixed_in 1.12.1).
  • High CVE-2026-27601 in underscore@1.8.3 enables DoS via unbounded recursion; unfixed (fixed_in 1.13.8).
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • Developer uses free webmail (gmail) with no verified business domain, reducing accountability.
  • Uninstall URL hijack flag set; uninstall redirect destination is unknown, possible tracking.

Evidence

  • cve_critical_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (ACE, critical); fixed_in 1.12.1 — version in use is below fix.
  • cve_high_underscore crx underscore@1.8.3 bundles CVE-2026-27601 (DoS, high); fixed_in 1.13.8.
  • privacy_policy_generic store Policy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_email_gmail store Developer email is sienori.firefox+c@gmail.com; free webmail, no verified business domain.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target unknown — potential post-uninstall tracking or redirect.
  • no_csp manifest content_security_policy is null; no CSP declared on MV3 extension (MV3 has strict default, no network penalty applied).
  • featured_by_google store is_featured_by_google=true; provides partial reputation signal but does not offset CVE exposure.
  • install_count_100k store 100,000 installs; moderate blast radius if CVE exploited or extension compromised.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Stores session data locally; expected for this category.
  • unlimitedStorage low Needed for large session archives; low standalone risk.
  • tabs medium Reads URLs/titles of all open tabs; core function but broad read access.
  • downloads medium Enables export of session files; slightly elevated due to file-system access.
  • identity low Used for OAuth sync; no scopes declared, limited exposure.
  • alarms low Schedules autosave; no sensitive data access.
  • offscreen low MV3 offscreen document; low risk absent code findings.

Pillar Scores

Permissions2.30
Reputation7.00
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA 068665223e21…
Force block — not fired
Score recovered no
Elapsed 46.4s