Next Experience Developer Tools
ilkodijinjhpdnnfpccijledlapkfmhc
Risk Score
4.60
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; no CSP to mitigate.
- eval() on user-controlled input in injected-script.js running on all pages is a direct code-execution risk.
- Privacy policy fetch failed (timeout); policy adequacy unverifiable — scored as no policy.
- cookies + <all_urls> host permission allows reading session cookies from every visited site.
- multiple new Function() constructors across 5 files with no CSP amplifies exploit surface.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1. No CSP present — ×1.5 amplifier applied.
- eval_user_input crx injected-script.js: eval(name) in proxy handler — direct eval of user-controlled variable on all pages.
- privacy_policy_fetch_failed store privacy_policy_classification.fetched==false (ReadTimeout); scored as +10.0 privacy.
- cookies_all_urls manifest cookies permission + *://*/* host_permissions + content_scripts:<all_urls> — broad session-token access.
- no_csp manifest content_security_policy is null on MV3 extension; amplifies CVE and code-quality risk.
- dom_xss_sink crx devtools-panel.js: innerHTML assigned from variable with no CSP and CVE present — FIX B +2.0 applied.
- developer_domain_no_resolve api developer_domain servicenow.onmicrosoft.com does not resolve; caps verified-publisher discount (not claimed anyway).
- installs_10k store 10,000 installs with high-capability permissions increases blast radius.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Local state persistence; limited risk alone.
- tabs medium Can read tab URLs and titles across all tabs.
- declarativeNetRequest medium Can modify/block network requests; scoped to rules.
- cookies high Cookie access paired with <all_urls> host permission is high-risk exfil surface.
- contextMenus low UI affordance only; no data access.
- *://*/* high Broad host access enables content injection and data reading on every site.
- content_scripts:<all_urls> high Scripts injected into every page; combined with eval/Function findings, high code-exec risk.
Pillar Scores
Permissions6.50
Reputation4.50
Network4.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality7.50
CVE Exposure7.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
034eaf9f4cc0…
Force block
— not fired
Score recovered
no
Elapsed
35.3s