Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SynQ for Spotify, YouTube, Amazon Music, more

jcdmcpefbebkldopabclefjaggejocff
Risk Score
5.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 50,000
Rating 4.0
Last updated 2026-06-07 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@ytmplus.app
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358, arbitrary code exec); additional high CVE (CVE-2026-27601); no CSP amplifies risk.
  • Brand impersonation: names Spotify, YouTube, Apple, Amazon without verified ownership; developer_name empty.
  • Privacy policy admits data collection AND third-party sharing but scoped policy lacks retention disclosure.
  • Hex-obfuscation in adapter/common JS files raises code-quality concern despite moderate obfuscation score.
  • Affiliate link via bit.ly in external hosts; dom_sink_innerhtml in 6 files with no CSP active.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 carries CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); fixed_in 1.13.8.
  • no_csp_cve_amplifier manifest content_security_policy is null; CVE amplifier x1.5 applies (DOM-manipulation lib + any high/critical CVE, no CSP).
  • brand_impersonation store brand_mention lists spotify/youtube/apple/amazon; confirmed_owner=false; not verified by any brand.
  • privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • hex_obfuscation crx adapter.4aa42674.js and common.3475fd4e.js contain 12+ consecutive hex-escapes; obfuscation_score=0.2.
  • dom_sink_innerhtml crx innerHTML assigned from variable in 6 files with no CSP; DOM-XSS risk elevated by CVE presence (FIX B).
  • affiliate_hit_bitly crx bit.ly in js_external_hosts flagged as affiliate/cloaking redirector by threat_intel.
  • verified_publisher store verified_publisher=true; discount capped at -1.0 due to monetization/affiliate hit per v3.5 invariant 0c/E.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Stores user preferences locally; minimal risk.
  • scripting medium Allows JS injection into pages; combined with content_scripts on music platforms.
  • content_scripts(*://music.amazon.com/*,*://music.apple.com/*,*://music.youtube.com/*,*://open.spotify.com/*,https://*.synqapp.io/redirect*) medium Runs code on 4 major music platforms and own redirect endpoint; broad but category-aligned.

Pillar Scores

Permissions1.50
Reputation6.50
Network3.00
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality5.00
CVE Exposure10.00

Scoring History

sssiedn84917f32dp727562726963xsx 4.38 Medium review 2026-09-11
v3.6 5.18 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA f46d3558cc4d…
Force block — not fired
Score recovered no
Elapsed 33.6s