House of the Dragon Wallpapers New Tab Extension
ijfeppdpekjggdpncdkmfllbgccggbio
Risk Score
7.56
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Google privacy policy used as proxy — does not scope to this extension; data collection and 3rd-party sharing admitted without extension context.
- NewTab override replaces every new tab; uninstall URL hijack to gameograf.com utm-tracked monetization URL.
- 9 bundled CVEs (all medium) across jquery@1.9.1, jquery@3.4.1, jquery-ui@1.12.1 — XSS risk with no CSP to mitigate.
- No CSP defined (MV3 default protects eval but not DOM-sink XSS from vulnerable jQuery/jQuery-UI).
- Developer name absent; 12 external JS hosts referenced including social platforms and jqueryui.com CDN.
Evidence
- privacy_policy_google_generic store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy pillar (v3.5 rule D).
- newtab_override manifest chrome_url_overrides.newtab=index.html; overrides every new tab, high-reach monetization surface.
- uninstall_url_hijack crx setUninstallURL to gameograf.com with UTM params; +3.0 webstore signal.
- cve_multiple_medium crx 9 medium CVEs across 3 library versions (jquery-ui@1.12.1, jquery@3.4.1, jquery@1.9.1); all unfixed in bundled versions.
- no_csp manifest content_security_policy=null; no CSP on MV3 extension with vulnerable jQuery/jQuery-UI DOM libs.
- install_url_hijack crx onInstalled opens index.html (internal); +2.0 webstore signal per install-URL-hijack rule.
- newtab_search_provider manifest search permission + topSites + newtab override = classic NewTab monetization shell pattern.
- developer_name_absent store developer_name is empty string; no 'Offered by' name visible; +1.0 reputation.
CVE Exposures (9)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.12.1 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2021-41183 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- search medium Allows reading/manipulating search queries; medium risk for NewTab monetization.
- topSites medium Reveals browsing habits; typical for NewTab but sensitive.
- unlimitedStorage low Allows unlimited local storage; low direct risk.
- storage low Standard local key-value storage; low risk.
- chrome_url_overrides.newtab high Replaces every new tab; high reach monetization surface.
Pillar Scores
Permissions4.00
Reputation4.50
Network3.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure5.25
Bookkeeping
Rubric v3.6
Scored at 2026-09-16 06:22
Listing SHA
6a6937392a10…
Force block
— not fired
Score recovered
no
Elapsed
—