Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tag Assistant

kejbdjndbnbjgmefkgdddjlbokphdefk
Risk Score
4.66
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 3,000,000
Rating 3.9
Last updated 2026-08-12
Manifest version MV3
CSP present ❌ no
Developer tag-assistant-publisher@google.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); unfixed version in production.
  • No content_security_policy on MV3 extension with <all_urls> and innerHTML sinks amplifies XSS risk.
  • 5 dom_sink_innerhtml_userctrl findings across polyfill and content script files with no CSP mitigation.
  • Privacy policy is generic Google policy (scope_extension=false); does not disclose what this extension collects.
  • 3M+ installs means high blast radius if vulnerabilities are exploited or extension is compromised.

Evidence

  • cve_critical_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code execution); fixed in 1.12.1.
  • cve_high_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via unlimited recursion); fixed in 1.13.8.
  • no_csp_with_innerhtml crx No CSP declared; 5 innerHTML-from-variable sinks in polyfills and content scripts.
  • generic_privacy_policy store Privacy policy is google.com/intl/en/policies/privacy/; scope_extension=false, no extension-specific disclosure.
  • broad_host_access manifest <all_urls> host permission with scripting enables read/write on all sites.
  • google_dev_email store Dev email tag-assistant-publisher@google.com; confirmed_owner=true, not impersonation.
  • monetization_hit_gtm crx www.googletagmanager.com in monetization_hits; contextually expected for Tag Assistant.
  • high_install_blast_radius store 3,000,000 installs; vulnerability exploitation would have wide reach.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • scripting medium Can inject scripts into pages; paired with <all_urls> elevates risk.
  • sidePanel low UI surface only; no data access.
  • storage low Local extension storage; no cross-site risk.
  • tabs medium Can read tab URLs and metadata; moderate privacy surface.
  • webNavigation medium Observes navigation events across all pages; privacy surface.
  • <all_urls> high Broad host access across all sites; enables reading/modifying any page content.

Pillar Scores

Permissions5.50
Reputation2.00
Network3.50
Webstore3.00
Maintenance0.00
Privacy9.00
Code Quality6.50
CVE Exposure7.00

Scoring History

<fsssiedxa&#x27;sssiedx 4.06 Medium review 2026-08-20
<fsssiedxifdsaxax><!--></ScRiPt>asddsssiedx 5.17 Medium review 2026-08-20
fsssiedx<sssiedx 5.06 Medium review 2026-08-20
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 4.49 Medium review 2026-08-05
v3.6&n996561=v945965 4.36 Medium review 2026-08-05
<fsssiedxa&#x22;sssiedx 4.31 Medium review 2026-07-30
<fsssiedxa xx psssiedx 4.79 Medium review 2026-07-30
<fsssiedxa$"sssiedx 4.36 Medium review 2026-07-30
&#x22;fsssiedxa xx psssiedx 4.75 Medium review 2026-07-30
&#x22;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.02 Medium review 2026-07-30
4.34 Medium review 2026-07-30
<fsssiedxa$'sssiedx 4.68 Medium review 2026-07-30
fsssiedxa<sssiedx 4.19 Medium review 2026-07-30
v3.6&n925424=v912310 4.53 Medium review 2026-07-29
fsssiedxc&#x27;sssiedx 4.20 Medium review 2026-07-28
sssieddrubricxsx 4.04 Medium review 2026-07-28
v3.6 4.66 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA 78f9f8b3c684…
Force block — not fired
Score recovered no
Elapsed 32.3s