Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

New Tab Redirect

icpgjfneehieebagbmdbhnlpiopdcmna
Risk Score
6.56
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 700,000
Rating 4.1
Last updated 2023-10-24 (34 months ago)
Manifest version MV3
CSP present ❌ no
Developer james.schubert@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@1.10.2 has 3 moderate XSS CVEs (fixed in 3.5.0); no CSP amplifies XSS exploitability via dynamic script creation and innerHTML sinks.
  • known-bad-host hit on github.com (URLHaus malware_download); extension lists github.com as external JS host.
  • New tab override with *://*/* host access gives full cross-origin read capability on every page the user visits.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing: scores maximum privacy risk.
  • Free-webmail developer (gmail.com) with no verified publisher badge and no business domain; install_url_hijack detected on install.

Evidence

  • known-bad-host hit on github.com crx threat_intel cve_findings_raw: URLHaus malware_download flag on github.com; extension bundles external JS from github.com.
  • jquery@1.10.2 bundled — 3 moderate CVEs + no CSP crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11023 all unpatched; no CSP present; DOM-manipulation lib triggers CVE v2 amplifier ×1.5.
  • script_src_dynamic in jquery + eval_user_input in angular crx Dynamic script tag creation and direct eval in vendored libs with no CSP guard — remote code loading risk.
  • New tab override + broad host permissions manifest chrome_url_overrides.newtab + host_permissions *://*/* grants full cross-origin capability from new tab context.
  • Privacy policy is generic Google account policy store scope_extension=false, data_collection=true, third_party_sharing=true — policy admits sharing without scoping to this extension.
  • Free-webmail developer, no verified publisher store developer_email=james.schubert@gmail.com; verified_publisher=false; no business domain resolvable.
  • install_url_hijack detected crx install_url_hijack=true; target=null. onInstalled opens a URL — exact destination unconfirmed but pattern is present.
  • Stale update + CVEs + MV3 (triple-stale partially applicable) store Last updated Oct 2023 (~19 months); CVEs unfixed; vendored libs well below fix versions — no remediation signal.

CVE Exposures (14)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.10.2 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.10.2 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.10.2 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
angular@1.2.13 angular@1.2.13 moderate 1.6.0 Cross-Site Scripting via JSONP
CVE-2023-26117 angular@1.2.13 moderate angular vulnerable to regular expression denial of service via the $resource ser
CVE-2023-26116 angular@1.2.13 moderate angular vulnerable to regular expression denial of service via the angular.copy(
CVE-2026-11998 angular@1.2.13 high Angular's deprecated package has a Cross-Site Scripting issue
CVE-2019-10768 angular@1.2.13 high 1.7.9 angular Prototype Pollution vulnerability
CVE-2025-0716 angular@1.2.13 low AngularJS improperly sanitizes SVG elements
CVE-2020-7676 angular@1.2.13 moderate 1.8.0 Angular vulnerable to Cross-site Scripting
CVE-2024-8373 angular@1.2.13 low AngularJS allows attackers to bypass common image source restrictions
CVE-2022-25869 angular@1.2.13 moderate Angular (deprecated package) Cross-site Scripting
CVE-2023-26118 angular@1.2.13 moderate angular vulnerable to regular expression denial of service via the <input type="
CVE-2019-14863 angular@1.2.13 moderate 1.5.0-beta.1 AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attribute

Permissions Breakdown

  • storage low Standard key-value storage; low standalone risk.
  • favicon low Read-only favicon access; minimal risk.
  • host_permissions: *://*/* high Broad host access across all URLs enables reading/injecting on any site.
  • host_permissions: file:/// medium Access to local filesystem URLs; can read local files if content scripts used.
  • chrome_url_overrides: newtab medium Replaces new tab page; high-visibility surface, monetization vector.

Pillar Scores

Permissions5.50
Reputation7.00
Network4.00
Webstore7.00
Maintenance3.50
Privacy10.00
Code Quality8.00
CVE Exposure7.50

Scoring History

fsssiedxa"sssiedx 7.14 High review 2026-08-10
v3.6 6.56 High block 2026-06-15
v3.4-rev 6.39 High review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 07:47
Listing SHA 5937c422ca5d…
Force block — not fired
Score recovered no
Elapsed 40.2s