Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

House of the Dragon Wallpapers New Tab Extension

ijfeppdpekjggdpncdkmfllbgccggbio
Risk Score
7.56
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 644
Rating 4.5
Last updated 2025-05-13 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google privacy policy used as proxy — does not scope to this extension; data collection and 3rd-party sharing admitted without extension context.
  • NewTab override replaces every new tab; uninstall URL hijack to gameograf.com utm-tracked monetization URL.
  • 9 bundled CVEs (all medium) across jquery@1.9.1, jquery@3.4.1, jquery-ui@1.12.1 — XSS risk with no CSP to mitigate.
  • No CSP defined (MV3 default protects eval but not DOM-sink XSS from vulnerable jQuery/jQuery-UI).
  • Developer name absent; 12 external JS hosts referenced including social platforms and jqueryui.com CDN.

Evidence

  • privacy_policy_google_generic store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy pillar (v3.5 rule D).
  • newtab_override manifest chrome_url_overrides.newtab=index.html; overrides every new tab, high-reach monetization surface.
  • uninstall_url_hijack crx setUninstallURL to gameograf.com with UTM params; +3.0 webstore signal.
  • cve_multiple_medium crx 9 medium CVEs across 3 library versions (jquery-ui@1.12.1, jquery@3.4.1, jquery@1.9.1); all unfixed in bundled versions.
  • no_csp manifest content_security_policy=null; no CSP on MV3 extension with vulnerable jQuery/jQuery-UI DOM libs.
  • install_url_hijack crx onInstalled opens index.html (internal); +2.0 webstore signal per install-URL-hijack rule.
  • newtab_search_provider manifest search permission + topSites + newtab override = classic NewTab monetization shell pattern.
  • developer_name_absent store developer_name is empty string; no 'Offered by' name visible; +1.0 reputation.

CVE Exposures (9)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.12.1 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2021-41183 jquery-ui@1.12.1 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • search medium Allows reading/manipulating search queries; medium risk for NewTab monetization.
  • topSites medium Reveals browsing habits; typical for NewTab but sensitive.
  • unlimitedStorage low Allows unlimited local storage; low direct risk.
  • storage low Standard local key-value storage; low risk.
  • chrome_url_overrides.newtab high Replaces every new tab; high reach monetization surface.

Pillar Scores

Permissions4.00
Reputation4.50
Network3.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure5.25

Bookkeeping

Rubric v3.6
Scored at 2026-09-16 06:22
Listing SHA 6a6937392a10…
Force block — not fired
Score recovered no
Elapsed