New Tab Redirect
icpgjfneehieebagbmdbhnlpiopdcmna
Risk Score
6.56
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- jquery@1.10.2 has 3 moderate XSS CVEs (fixed in 3.5.0); no CSP amplifies XSS exploitability via dynamic script creation and innerHTML sinks.
- known-bad-host hit on github.com (URLHaus malware_download); extension lists github.com as external JS host.
- New tab override with *://*/* host access gives full cross-origin read capability on every page the user visits.
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing: scores maximum privacy risk.
- Free-webmail developer (gmail.com) with no verified publisher badge and no business domain; install_url_hijack detected on install.
Evidence
- known-bad-host hit on github.com crx threat_intel cve_findings_raw: URLHaus malware_download flag on github.com; extension bundles external JS from github.com.
- jquery@1.10.2 bundled — 3 moderate CVEs + no CSP crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11023 all unpatched; no CSP present; DOM-manipulation lib triggers CVE v2 amplifier ×1.5.
- script_src_dynamic in jquery + eval_user_input in angular crx Dynamic script tag creation and direct eval in vendored libs with no CSP guard — remote code loading risk.
- New tab override + broad host permissions manifest chrome_url_overrides.newtab + host_permissions *://*/* grants full cross-origin capability from new tab context.
- Privacy policy is generic Google account policy store scope_extension=false, data_collection=true, third_party_sharing=true — policy admits sharing without scoping to this extension.
- Free-webmail developer, no verified publisher store developer_email=james.schubert@gmail.com; verified_publisher=false; no business domain resolvable.
- install_url_hijack detected crx install_url_hijack=true; target=null. onInstalled opens a URL — exact destination unconfirmed but pattern is present.
- Stale update + CVEs + MV3 (triple-stale partially applicable) store Last updated Oct 2023 (~19 months); CVEs unfixed; vendored libs well below fix versions — no remediation signal.
CVE Exposures (14)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.10.2 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.10.2 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.10.2 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| angular@1.2.13 | angular@1.2.13 | moderate | 1.6.0 | Cross-Site Scripting via JSONP |
| CVE-2023-26117 | angular@1.2.13 | moderate | — | angular vulnerable to regular expression denial of service via the $resource ser |
| CVE-2023-26116 | angular@1.2.13 | moderate | — | angular vulnerable to regular expression denial of service via the angular.copy( |
| CVE-2026-11998 | angular@1.2.13 | high | — | Angular's deprecated package has a Cross-Site Scripting issue |
| CVE-2019-10768 | angular@1.2.13 | high | 1.7.9 | angular Prototype Pollution vulnerability |
| CVE-2025-0716 | angular@1.2.13 | low | — | AngularJS improperly sanitizes SVG elements |
| CVE-2020-7676 | angular@1.2.13 | moderate | 1.8.0 | Angular vulnerable to Cross-site Scripting |
| CVE-2024-8373 | angular@1.2.13 | low | — | AngularJS allows attackers to bypass common image source restrictions |
| CVE-2022-25869 | angular@1.2.13 | moderate | — | Angular (deprecated package) Cross-site Scripting |
| CVE-2023-26118 | angular@1.2.13 | moderate | — | angular vulnerable to regular expression denial of service via the <input type=" |
| CVE-2019-14863 | angular@1.2.13 | moderate | 1.5.0-beta.1 | AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attribute |
Permissions Breakdown
- storage low Standard key-value storage; low standalone risk.
- favicon low Read-only favicon access; minimal risk.
- host_permissions: *://*/* high Broad host access across all URLs enables reading/injecting on any site.
- host_permissions: file:/// medium Access to local filesystem URLs; can read local files if content scripts used.
- chrome_url_overrides: newtab medium Replaces new tab page; high-visibility surface, monetization vector.
Pillar Scores
Permissions5.50
Reputation7.00
Network4.00
Webstore7.00
Maintenance3.50
Privacy10.00
Code Quality8.00
CVE Exposure7.50
Scoring History
| fsssiedxa"sssiedx | 7.14 | High | review | 2026-08-10 |
| v3.6 | 6.56 | High | block | 2026-06-15 |
| v3.4-rev | 6.39 | High | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 07:47
Listing SHA
5937c422ca5d…
Force block
— not fired
Score recovered
no
Elapsed
40.2s