Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Adblock Web - Adblocker for Chrome

jhkhlgaomejplkanglolfpcmfknnomle
Risk Score
6.44
Risk Level: High
Recommendation: 🚫 BLOCK
Category Adblock
Installs 10,000
Rating 4.5
Last updated 2025-11-19 (9 months ago)
Manifest version MV2
CSP present ❌ no
Developer phuongrangnao@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • 11 medium-severity CVEs across 3 outdated jQuery versions (1.7.1, 1.11.0, 3.1.1) with no CSP — XSS amplifier applies, CVE pillar capped at 10.0.
  • Uninstall and install URL hijack both present — classic monetization/tracking shell pattern.
  • Free Gmail dev email ('phuongrangnao@gmail.com') for extension claiming corporate name 'uadblock Inc'; no verified publisher.
  • No content_security_policy (MV2+no CSP): +2.0 network penalty; script_src_dynamic findings in multiple files compound risk.
  • Privacy policy hosted on Google Sites (free hosting), no retention disclosure, third_party_silence=true.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL hijacks detected — webstore +3.0 each per rubric.
  • free_webmail_dev store Developer email phuongrangnao@gmail.com is free webmail; claimed name 'uadblock Inc' unverifiable.
  • no_csp_mv2 manifest content_security_policy is null on MV2 extension — +2.0 network penalty applied.
  • cve_jquery_multiple crx 11 moderate CVEs across jquery 1.7.1, 1.11.0, 3.1.1; all below fixed_in versions; ×1.5 amplifier (no CSP + DOM lib).
  • script_src_dynamic crx Dynamic script element creation in 3 JS files — remote code loading risk even if in jQuery internals.
  • privacy_policy_free_hosting_no_retention api Policy on sites.google.com; scope_extension=true, data_collection=true, retention=false, third_party_silence=true.
  • broad_host_webrequest_blocking manifest http://*/* + https://*/* + webRequestBlocking: can intercept and modify all browser traffic.
  • identifier_obfuscation crx _0xABCD-style identifiers in domain/js/globalconstent.js — obfuscator output outside bundled libraries.

CVE Exposures (11)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.11.0 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.11.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.11.0 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2012-6708 jquery@1.7.1 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2019-11358 jquery@1.7.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.7.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-7656 jquery@1.7.1 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2015-9251 jquery@1.7.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2019-11358 jquery@3.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Can enumerate open tabs and their URLs.
  • http://*/* high Broad host access to all HTTP sites; content injection possible.
  • https://*/* high Broad host access to all HTTPS sites; content injection possible.
  • contextMenus low Adds items to right-click menu; low standalone risk.
  • webRequest high Can observe all network requests across all sites.
  • webRequestBlocking high Can intercept and modify/block requests across all sites.
  • webNavigation medium Tracks navigation events across all pages.
  • storage low Local extension storage; standard for settings.
  • unlimitedStorage low No size cap on local storage; minor risk.
  • notifications low Can display desktop notifications.

Pillar Scores

Permissions6.50
Reputation6.50
Network6.00
Webstore7.00
Maintenance3.50
Privacy2.00
Code Quality7.00
CVE Exposure10.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:47
Listing SHA 1736d90fe0cc…
Force block — not fired
Score recovered no
Elapsed