Nayeon Twice K-pop Wallpapers New Tab by Gameograf
kaaokglchipngiahokpikpjoipacmmaa
Risk Score
5.97
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope to this extension; admits data collection and 3rd-party sharing (max privacy score).
- New-tab override with uninstall URL hijack and install URL hijack: classic monetization shell pattern.
- Nine medium-severity CVEs across three bundled jQuery/jQuery-UI versions, all below fixed versions.
- No CSP (csp_present=false) on MV3 extension with CVE-affected DOM-manipulation libs increases XSS exploitability.
- 16 months since last update with vulnerable JS libraries still bundled; stale+CVE fingerprint.
Evidence
- uninstall_url_hijack + install_url_hijack crx Extension sets uninstall URL to gameograf.com/nayeon-twice-k-pop-wallpapers-new-tab/ and opens index.html on install — monetization shell indicators.
- generic_privacy_policy store Privacy URL is Google's own account policy; fetched, scope_extension=false, data_collection=true, third_party_sharing=true → D clause applies, score 10.
- newtab_override manifest chrome_url_overrides.newtab = index.html; high-visibility page replacement on every new tab.
- cve_bundled_libs crx 9 moderate CVEs across jquery@1.9.1, jquery@3.4.1, jquery-ui@1.12.1; none patched to fixed_in versions.
- no_csp manifest csp_present=false on MV3 extension with CVE-affected jQuery libs; raises XSS exploitability.
- stale_extension store 16 months since last update; vulnerable libraries still bundled.
- no_developer_name store developer_name is empty string; reduces accountability.
- 12_external_js_hosts crx js_external_hosts lists 12 domains (whatsapp, pinterest, crazycraftz, twitter, etc.) broadening network attack surface.
CVE Exposures (9)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.12.1 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2021-41183 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- topSites medium Reads user's most visited sites; NewTab extension common but exposes browsing habits.
- unlimitedStorage low Allows unbounded local storage; low direct risk but enables large local caching.
- storage low Standard key-value storage; low risk on its own.
- chrome_url_overrides.newtab medium Replaces new-tab page; high-visibility hijack surface, monetization vector.
Pillar Scores
Permissions4.30
Reputation5.50
Network2.50
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure4.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 06:26
Listing SHA
ba3d0ad25782…
Force block
— not fired
Score recovered
no
Elapsed
—