Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Privacy Surf

jgacjemaefpgfcjecoogiphcoallkbka
Risk Score
4.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 3
Rating
Last updated 2026-07-29 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer extensiongroup1142@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override sets privacysurf.co/redirect as default engine — classic search-hijack monetization pattern.
  • Developer is a numbered Gmail alias (extensiongroup1142@gmail.com) with no developer name or verified business identity.
  • Privacy policy URL points to the extension's own Chrome Web Store page, not a real policy — scope/retention undisclosed.
  • declarativeNetRequestWithHostAccess enables silent network request redirection without user visibility.
  • Only 3 installs with a high-capability permission combination raises tail-attack-surface concern.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to https://privacysurf.co/redirect/search?q={searchTerms}, is_default=true.
  • developer_identity store Developer email is extensiongroup1142@gmail.com (numbered alias), developer_name is empty, no business domain.
  • privacy_policy_invalid store Privacy policy URL resolves to the extension's own CWS listing page, not a standalone policy document.
  • declarativeNetRequestWithHostAccess manifest HIGH permission allowing network request interception/redirect paired with search override.
  • install_perm_anomaly api 3 installs with has_high_tier_permission=true and small_install_high_perm=true flagged by anomaly check.
  • search_engine_count api Extension contacts duckduckgo.com and search.yahoo.com (2 external search engines) consistent with redirect aggregation.
  • verified_publisher store Verified publisher badge present but developer_name empty and Gmail alias undermines trust signal.
  • no_csp manifest content_security_policy is null; MV3 provides some default but no explicit policy declared.

Permissions Breakdown

  • storage low Stores local settings; low standalone risk.
  • declarativeNetRequestWithHostAccess high Can intercept and redirect network requests; high capability for traffic manipulation.
  • host_permissions: *://privacysurf.co/* medium Narrow host scope but combined with declarativeNetRequestWithHostAccess enables redirect control.
  • chrome_settings_overrides.search_provider (is_default=true) high Forces default search engine change to privacysurf.co/redirect, classic search-hijack vector.

Pillar Scores

Permissions7.00
Reputation7.50
Network0.00
Webstore5.50
Maintenance0.00
Privacy6.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:35
Listing SHA 9c7ce455a679…
Force block — not fired
Score recovered no
Elapsed