Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bookmark Manager

idakfiahffeejfhghndaboolmmhbnepn
Risk Score
4.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 60,000
Rating 3.4
Last updated 2026-06-06
Manifest version MV3
CSP present ❌ no
Developer aureollabs@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing without extension-specific scope — worst-case privacy posture.
  • 7 unpatched medium-severity CVEs in bundled jquery@3.3.1 and jquery-ui@1.12.1; DOM-XSS sink in sessions.js amplifies risk.
  • DOM-XSS sink (innerHTML from variable) combined with no CSP and vulnerable jQuery raises exploitability.
  • <all_urls> host access combined with history and tabs grants broad surveillance capability.
  • Developer is free-webmail gmail address with no developer name disclosed, reducing accountability.

Evidence

  • privacy_policy_admits_collection_and_sharing_no_scope api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D → +10.0 privacy.
  • 7_medium_cves_in_jquery_jquery-ui crx jquery@3.3.1 (3 CVEs) and jquery-ui@1.12.1 (4 CVEs), all moderate, all below fixed_in versions.
  • dom_xss_sink_no_csp crx innerHTML from user-controlled var in sessions.js; csp_present=false triggers +2.0 code quality penalty (FIX B).
  • broad_host_access_with_history manifest <all_urls> + history + tabs; no justified-broad discount (not an adblock/VPN/privacy category).
  • free_webmail_dev_no_name store developer_email=aureollabs@gmail.com, developer_name empty; gmail dev with no business website.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; discounts applied but capped where applicable.
  • cve_amplifier_no_csp_jquery crx No CSP + medium CVEs in jQuery (DOM-manipulation lib): ×1.5 CVE amplifier applied → cve_pillar=5.0.
  • rating_below_3_5 store Rating 3.4; count unknown. Below 4.5 threshold so no positive adjustment; insufficient data for negative trigger.

CVE Exposures (7)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.12.1 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2021-41183 jquery-ui@1.12.1 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Allows reading tab URLs/titles; reasonable for bookmark manager.
  • history medium Full browsing history access; broad capability for a bookmark tool.
  • bookmarks medium Core stated function; read/write all bookmarks.
  • <all_urls> high Host access to all URLs; broad capability paired with history/tabs.
  • storage low Local extension data storage; low risk.
  • favicon low Read favicon URLs; minimal risk.
  • sidePanel low UI surface only; low risk.

Pillar Scores

Permissions6.00
Reputation5.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure5.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA 77dd4c13fdca…
Force block — not fired
Score recovered no
Elapsed 53.4s