Tab Session Manager
iaiomicjabeggjcfkbimgmglanimpnae
Risk Score
4.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 allows arbitrary code execution; unfixed (fixed_in 1.12.1).
- High CVE-2026-27601 in underscore@1.8.3 enables DoS via unbounded recursion; unfixed (fixed_in 1.13.8).
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- Developer uses free webmail (gmail) with no verified business domain, reducing accountability.
- Uninstall URL hijack flag set; uninstall redirect destination is unknown, possible tracking.
Evidence
- cve_critical_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (ACE, critical); fixed_in 1.12.1 — version in use is below fix.
- cve_high_underscore crx underscore@1.8.3 bundles CVE-2026-27601 (DoS, high); fixed_in 1.13.8.
- privacy_policy_generic store Policy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_email_gmail store Developer email is sienori.firefox+c@gmail.com; free webmail, no verified business domain.
- uninstall_url_hijack crx uninstall_url_hijack=true; target unknown — potential post-uninstall tracking or redirect.
- no_csp manifest content_security_policy is null; no CSP declared on MV3 extension (MV3 has strict default, no network penalty applied).
- featured_by_google store is_featured_by_google=true; provides partial reputation signal but does not offset CVE exposure.
- install_count_100k store 100,000 installs; moderate blast radius if CVE exploited or extension compromised.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Stores session data locally; expected for this category.
- unlimitedStorage low Needed for large session archives; low standalone risk.
- tabs medium Reads URLs/titles of all open tabs; core function but broad read access.
- downloads medium Enables export of session files; slightly elevated due to file-system access.
- identity low Used for OAuth sync; no scopes declared, limited exposure.
- alarms low Schedules autosave; no sensitive data access.
- offscreen low MV3 offscreen document; low risk absent code findings.
Pillar Scores
Permissions2.30
Reputation7.00
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
068665223e21…
Force block
— not fired
Score recovered
no
Elapsed
46.4s