Google Meet AI Translate
jffmadlbndodbiimdmjhmfcmlcpinkfb
Risk Score
5.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: uses 'Google' in name/title without verified ownership of Google brand.
- Privacy policy on zerocoder.com does not scope to this extension and lacks retention disclosure.
- Three medium CVEs in bundled jquery@3.3.1 (XSS); no CSP amplifies DOM-sink risk.
- Extension contacts raw IP (5.44.46.205) and zerocoder.com — 3 external hosts across 3 countries.
- Developer name absent; policy domain (zerocoder.com) differs from dev domain (donenote.com).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands=['google'], confirmed_owner=false; not verified or featured.
- cve_jquery_3.3.1 crx 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) in inline jquery@3.3.1; fixed_in 3.5.0.
- no_csp crx content_security_policy is null; MV3 but no explicit CSP declared, amplifying XSS/DOM-sink risk.
- external_hosts crx js_external_hosts: 5.44.46.205 (raw IP, AE), google.com (US), zerocoder.com (DE) — 3 countries.
- privacy_policy_scope_mismatch api Policy fetched from zerocoder.com; scope_extension=false, data_collection=false, retention=false.
- dom_xss_sink crx popup.js assigns innerHTML from variable tempHTML — DOM-XSS sink with no CSP guard.
- developer_name_missing store developer_name is empty string; email hi@donenote.com but policy hosted on zerocoder.com.
- months_since_update_15 store Last updated March 2025; 15 months stale — maintenance score 6.0 (12-24mo band).
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- scripting medium Can inject JS into active tab; medium-impact without broad host permissions.
- activeTab low Transient access to current tab only; low risk in isolation.
Pillar Scores
Permissions1.30
Reputation7.00
Network3.50
Webstore5.50
Maintenance6.00
Privacy9.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA
685475aa6fcb…
Force block
— not fired
Score recovered
no
Elapsed
24.9s