BMW M3 GTR Legend Live Wallpaper
kbamolgogdnljebbpgonfnobkdmmaoib
Risk Score
5.59
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- NewTab override replaces every new-tab page — primary monetization surface; paired with 'search' permission.
- Privacy policy is Google's generic policy (scope_extension=false, admits data collection+3rd-party sharing) — worst-case privacy score.
- Uninstall and install URL hijacks redirect users to gameograf.com tracking URLs.
- No developer name listed; 'Offered by' field empty despite verified-publisher badge.
- Two innerHTML DOM-XSS sinks with no CSP present increase XSS exploitability.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set to newtab.html — replaces every new tab for 1,000 users.
- uninstall_url_hijack crx setUninstallURL to gameograf.com with UTM tracking params on uninstall.
- install_url_hijack crx onInstalled opens gameograf.com with UTM tracking params on install.
- generic_privacy_policy api Privacy policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- no_developer_name store developer_name is empty string despite verified_publisher=true.
- dom_xss_no_csp crx Two innerHTML sinks (popup.js, calendar.js) with csp_present=false — XSS risk elevated.
- new_tab_monetization_shell store Wallpaper/theme shell with newtab override + search permission + install/uninstall tracking URLs.
- verified_publisher_cap store Verified publisher discount capped at -1.0 per v3.5(E): privacy policy admits data collection via generic Google policy.
Permissions Breakdown
- search medium Allows reading/manipulating search queries; paired with newtab override amplifies risk.
- chrome_url_overrides.newtab high Replaces every new-tab page; primary monetization surface for wallpaper/NewTab shells.
- host_permissions: https://api.gameograf.com/* low Scoped to dev-controlled API domain only; limited blast radius.
Pillar Scores
Permissions5.00
Reputation5.50
Network2.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:10
Listing SHA
da546e89e02e…
Force block
— not fired
Score recovered
no
Elapsed
—