Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Extensity

jjmflmamggggndanpgfnpelongoepncg
Risk Score
7.00
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category DeveloperTools
Installs 200,000
Rating 4.8
Last updated 2024-09-02 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer dev@sergiokas.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
  • Privacy policy is Google's generic account policy — not scoped to this extension; collects and shares data per policy.
  • underscore@1.13.7 has a high-severity CVE (DoS via unlimited recursion); fix available in 1.13.8.
  • management permission allows full control over all installed extensions — high-impact capability.
  • Extension is 21 months stale; verified-publisher/featured discount capped at -1.0 under v3.5 invariant 0c.

Evidence

  • management_permission manifest management declared — can enumerate/enable/disable all extensions on device.
  • generic_google_privacy_policy store Privacy policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • high_cve_in_bundled_lib crx underscore@1.13.7 — CVE-2026-27601 high severity; fixed_in 1.13.8 not yet applied.
  • function_constructor_in_libs crx new Function() in underscore-min.js and knockout-3.5.1.js; in library template/parse paths.
  • stale_extension store Last updated Sep 2024; 21 months since update triggers +6.0 maintenance penalty.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discount capped at -1.0 (stale >18mo).
  • brand_impersonation_signal store brand_mention: google referenced, is_impersonation=true, confirmed_owner=false.
  • no_csp manifest csp_present=false on MV3; new Function() findings present — dom_sink amplifier applies.

CVE Exposures (1)

CVELibrarySeverity Fixed inSummary
CVE-2026-27601 underscore@1.13.7 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • management high Can enumerate, enable, disable, or uninstall all installed extensions — broad system control.
  • storage low Local key-value storage; no cross-site or user-data risk on its own.

Pillar Scores

Permissions7.50
Reputation3.50
Network2.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA b2fb1cf0a075…
Force block — not fired
Score recovered no
Elapsed 27.8s