SynQ for Spotify, YouTube, Amazon Music, more
jcdmcpefbebkldopabclefjaggejocff
Risk Score
5.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358, arbitrary code exec); additional high CVE (CVE-2026-27601); no CSP amplifies risk.
- Brand impersonation: names Spotify, YouTube, Apple, Amazon without verified ownership; developer_name empty.
- Privacy policy admits data collection AND third-party sharing but scoped policy lacks retention disclosure.
- Hex-obfuscation in adapter/common JS files raises code-quality concern despite moderate obfuscation score.
- Affiliate link via bit.ly in external hosts; dom_sink_innerhtml in 6 files with no CSP active.
Evidence
- critical_cve_underscore crx underscore@1.8.3 carries CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); fixed_in 1.13.8.
- no_csp_cve_amplifier manifest content_security_policy is null; CVE amplifier x1.5 applies (DOM-manipulation lib + any high/critical CVE, no CSP).
- brand_impersonation store brand_mention lists spotify/youtube/apple/amazon; confirmed_owner=false; not verified by any brand.
- privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- hex_obfuscation crx adapter.4aa42674.js and common.3475fd4e.js contain 12+ consecutive hex-escapes; obfuscation_score=0.2.
- dom_sink_innerhtml crx innerHTML assigned from variable in 6 files with no CSP; DOM-XSS risk elevated by CVE presence (FIX B).
- affiliate_hit_bitly crx bit.ly in js_external_hosts flagged as affiliate/cloaking redirector by threat_intel.
- verified_publisher store verified_publisher=true; discount capped at -1.0 due to monetization/affiliate hit per v3.5 invariant 0c/E.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Stores user preferences locally; minimal risk.
- scripting medium Allows JS injection into pages; combined with content_scripts on music platforms.
- content_scripts(*://music.amazon.com/*,*://music.apple.com/*,*://music.youtube.com/*,*://open.spotify.com/*,https://*.synqapp.io/redirect*) medium Runs code on 4 major music platforms and own redirect endpoint; broad but category-aligned.
Pillar Scores
Permissions1.50
Reputation6.50
Network3.00
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality5.00
CVE Exposure10.00
Scoring History
| sssiedn84917f32dp727562726963xsx | 4.38 | Medium | review | 2026-09-11 |
| v3.6 | 5.18 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA
f46d3558cc4d…
Force block
— not fired
Score recovered
no
Elapsed
33.6s