Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Nayeon Twice K-pop Wallpapers New Tab by Gameograf

kaaokglchipngiahokpikpjoipacmmaa
Risk Score
5.97
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 720
Rating 5.0
Last updated 2025-05-01 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not scope to this extension; admits data collection and 3rd-party sharing (max privacy score).
  • New-tab override with uninstall URL hijack and install URL hijack: classic monetization shell pattern.
  • Nine medium-severity CVEs across three bundled jQuery/jQuery-UI versions, all below fixed versions.
  • No CSP (csp_present=false) on MV3 extension with CVE-affected DOM-manipulation libs increases XSS exploitability.
  • 16 months since last update with vulnerable JS libraries still bundled; stale+CVE fingerprint.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Extension sets uninstall URL to gameograf.com/nayeon-twice-k-pop-wallpapers-new-tab/ and opens index.html on install — monetization shell indicators.
  • generic_privacy_policy store Privacy URL is Google's own account policy; fetched, scope_extension=false, data_collection=true, third_party_sharing=true → D clause applies, score 10.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; high-visibility page replacement on every new tab.
  • cve_bundled_libs crx 9 moderate CVEs across jquery@1.9.1, jquery@3.4.1, jquery-ui@1.12.1; none patched to fixed_in versions.
  • no_csp manifest csp_present=false on MV3 extension with CVE-affected jQuery libs; raises XSS exploitability.
  • stale_extension store 16 months since last update; vulnerable libraries still bundled.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • 12_external_js_hosts crx js_external_hosts lists 12 domains (whatsapp, pinterest, crazycraftz, twitter, etc.) broadening network attack surface.

CVE Exposures (9)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.12.1 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2021-41183 jquery-ui@1.12.1 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • topSites medium Reads user's most visited sites; NewTab extension common but exposes browsing habits.
  • unlimitedStorage low Allows unbounded local storage; low direct risk but enables large local caching.
  • storage low Standard key-value storage; low risk on its own.
  • chrome_url_overrides.newtab medium Replaces new-tab page; high-visibility hijack surface, monetization vector.

Pillar Scores

Permissions4.30
Reputation5.50
Network2.50
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure4.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 06:26
Listing SHA ba3d0ad25782…
Force block — not fired
Score recovered no
Elapsed