Telegram Blur - Advanced Telegram Web Privacy
jlkmjnjncpcplnajcbibddpkmbficecj
Risk Score
2.47
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; collects and shares data with third parties.
- Brand impersonation: 'Telegram' mentioned in name/description by unverified developer with gmail address.
- Developer identity weak: name 'ext', free webmail only, no business website or verified publisher status.
- No content security policy (MV3 default mitigates but adds no explicit script-src restriction).
- installs > 10,000 with unverified developer increases blast radius if extension is ever compromised.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; 'Telegram' in title/description; developer is not confirmed owner.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_identity_weak store Developer name 'ext', email fahd.dev.rg@gmail.com; free webmail, no business domain, no verified publisher.
- no_csp manifest content_security_policy is null; MV3 applies strict default but no explicit CSP declared.
- narrow_host_permissions manifest host_permissions scoped to https://web.telegram.org/ only; matches stated privacy/blur function.
- code_clean crx code_findings_raw empty, obfuscation_score=0.0, no CVEs, no external JS hosts beyond web.telegram.org.
- recently_updated store Last updated June 10, 2026; months_since_update=0; maintenance risk minimal.
- no_threat_intel_hits api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], no bad-host or ad-tech signals.
Permissions Breakdown
- storage low Stores user preferences locally; standard low-risk permission.
- scripting medium Allows injecting scripts into pages; scoped to web.telegram.org only.
- host: https://web.telegram.org/ medium Narrow single-site scope; matches stated function of blurring Telegram messages.
Pillar Scores
Permissions1.80
Reputation7.50
Network0.00
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
54734d8c0147…
Force block
— not fired
Score recovered
no
Elapsed
19.7s