Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Care.Sale

jaioobipjdejpeckgojiojjahmkiaihp
Risk Score
7.03
Risk Level: High
Recommendation: 🚫 BLOCK
Category Shopping
Installs 11
Rating
Last updated 2024-07-21 (25 months ago)
Manifest version MV3
CSP present ❌ no
Developer jon@status77.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • 4 critical CVEs in bundled crypto-js, lodash, underscore with no CSP; arbitrary code execution risk on every visited page.
  • Privacy policy URL returns HTTP error (fetch_error); no verifiable data handling disclosure for an extension with full cookie+host access.
  • webRequest + cookies + <all_urls> on all HTTP/HTTPS sites enables complete session and credential interception.
  • Uninstall URL hijack present; extension redirects users to third-party URL on removal — classic monetization/tracking signal.
  • 25 months since last update; stale extension with critical CVEs in bundled libs runs on all visited sites.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() to third-party detected; classic monetization shell pattern.
  • critical_cves crx crypto-js (2 critical), lodash (1 critical), underscore (1 critical) bundled at vulnerable versions.
  • privacy_policy_fetch_error store https://care.sale/privacy returns HTTPError; policy not verifiable — treated as no policy.
  • broad_host_plus_cookies_webrequest manifest cookies + webRequest + http://*/* + https://*/* = full network surveillance capability.
  • stale_extension store Last updated July 2024; 25 months since update with critical CVE-laden deps.
  • no_csp manifest content_security_policy is null; no CSP amplifies CVE risk in DOM-manipulation libs (lodash, underscore).
  • small_install_high_perm_anomaly api Only 11 installs but requests HIGH-tier permissions (webRequest, cookies, <all_urls>).
  • no_developer_name store developer_name is empty string; accountability gap for a high-capability extension.

CVE Exposures (17)

CVELibrarySeverity Fixed inSummary
@sentry/browser@unknown @sentry/browser@unknown moderate 8.33.0 Sentry SDK Prototype Pollution gadget in JavaScript SDKs
CVE-2026-71851 crypto-js@unknown critical 4.0.0 crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerabl
CVE-2023-46233 crypto-js@unknown critical 4.2.0 crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker
CVE-2021-23337 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2026-4800 lodash@unknown high 4.17.21 Command Injection in lodash
CVE-2018-16487 lodash@unknown high 4.17.11 Prototype Pollution in lodash
CVE-2025-13465 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2026-2950 lodash@unknown moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2018-3721 lodash@unknown moderate 4.17.5 Prototype Pollution in lodash
CVE-2019-10744 lodash@unknown critical 4.17.12 Prototype Pollution in lodash
CVE-2017-18214 moment@unknown high 2.19.3 Regular Expression Denial of Service in moment
CVE-2016-4055 moment@unknown moderate 2.11.2 Regular Expression Denial of Service in moment
CVE-2022-24785 moment@unknown high 2.29.2 Path Traversal: 'dir/../../filename' in moment.locale
CVE-2026-41907 uuid@unknown moderate 11.1.1 uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2026-41988 uuid@unknown moderate 11.1.1 uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Local data persistence; low standalone risk.
  • tabs medium Access to tab URLs and metadata; combined with broad host access is elevated.
  • notifications low Can display notifications; limited harm alone.
  • background medium Persistent background execution; keeps extension alive at all times.
  • webRequest high Can observe all network requests across all URLs; surveillance capability.
  • cookies high Read/write cookies on all sites; combined with <all_urls> = high credential risk.
  • unlimitedStorage low Allows large local data store; low direct harm.
  • http://*/* high Broad host access to all HTTP sites; enables content injection and interception.
  • https://*/* high Broad host access to all HTTPS sites including banking/auth; high data exfil risk.

Pillar Scores

Permissions9.00
Reputation6.50
Network4.00
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure10.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 16:05
Listing SHA ad2833bdd64d…
Force block — not fired
Score recovered no
Elapsed