Care.Sale
jaioobipjdejpeckgojiojjahmkiaihp
Risk Score
7.03
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- 4 critical CVEs in bundled crypto-js, lodash, underscore with no CSP; arbitrary code execution risk on every visited page.
- Privacy policy URL returns HTTP error (fetch_error); no verifiable data handling disclosure for an extension with full cookie+host access.
- webRequest + cookies + <all_urls> on all HTTP/HTTPS sites enables complete session and credential interception.
- Uninstall URL hijack present; extension redirects users to third-party URL on removal — classic monetization/tracking signal.
- 25 months since last update; stale extension with critical CVEs in bundled libs runs on all visited sites.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() to third-party detected; classic monetization shell pattern.
- critical_cves crx crypto-js (2 critical), lodash (1 critical), underscore (1 critical) bundled at vulnerable versions.
- privacy_policy_fetch_error store https://care.sale/privacy returns HTTPError; policy not verifiable — treated as no policy.
- broad_host_plus_cookies_webrequest manifest cookies + webRequest + http://*/* + https://*/* = full network surveillance capability.
- stale_extension store Last updated July 2024; 25 months since update with critical CVE-laden deps.
- no_csp manifest content_security_policy is null; no CSP amplifies CVE risk in DOM-manipulation libs (lodash, underscore).
- small_install_high_perm_anomaly api Only 11 installs but requests HIGH-tier permissions (webRequest, cookies, <all_urls>).
- no_developer_name store developer_name is empty string; accountability gap for a high-capability extension.
CVE Exposures (17)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| @sentry/browser@unknown | @sentry/browser@unknown | moderate | 8.33.0 | Sentry SDK Prototype Pollution gadget in JavaScript SDKs |
| CVE-2026-71851 | crypto-js@unknown | critical | 4.0.0 | crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerabl |
| CVE-2023-46233 | crypto-js@unknown | critical | 4.2.0 | crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker |
| CVE-2021-23337 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2026-4800 | lodash@unknown | high | 4.17.21 | Command Injection in lodash |
| CVE-2018-16487 | lodash@unknown | high | 4.17.11 | Prototype Pollution in lodash |
| CVE-2025-13465 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2026-2950 | lodash@unknown | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2018-3721 | lodash@unknown | moderate | 4.17.5 | Prototype Pollution in lodash |
| CVE-2019-10744 | lodash@unknown | critical | 4.17.12 | Prototype Pollution in lodash |
| CVE-2017-18214 | moment@unknown | high | 2.19.3 | Regular Expression Denial of Service in moment |
| CVE-2016-4055 | moment@unknown | moderate | 2.11.2 | Regular Expression Denial of Service in moment |
| CVE-2022-24785 | moment@unknown | high | 2.29.2 | Path Traversal: 'dir/../../filename' in moment.locale |
| CVE-2026-41907 | uuid@unknown | moderate | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| CVE-2026-41988 | uuid@unknown | moderate | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Local data persistence; low standalone risk.
- tabs medium Access to tab URLs and metadata; combined with broad host access is elevated.
- notifications low Can display notifications; limited harm alone.
- background medium Persistent background execution; keeps extension alive at all times.
- webRequest high Can observe all network requests across all URLs; surveillance capability.
- cookies high Read/write cookies on all sites; combined with <all_urls> = high credential risk.
- unlimitedStorage low Allows large local data store; low direct harm.
- http://*/* high Broad host access to all HTTP sites; enables content injection and interception.
- https://*/* high Broad host access to all HTTPS sites including banking/auth; high data exfil risk.
Pillar Scores
Permissions9.00
Reputation6.50
Network4.00
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure10.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 16:05
Listing SHA
ad2833bdd64d…
Force block
— not fired
Score recovered
no
Elapsed
—