TikTok Enhancer - Editing News & Re:TikTok
kflflcpnnkojolplllfgcjobkgjmpdon
Risk Score
4.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: extension names TikTok in title but confirmed_owner=false; not verified for TikTok brand.
- cookies + scripting + full tiktok.com host access enables TikTok session/credential exfiltration.
- Privacy policy not scoped to this extension; data_collection unaddressed, third_party_sharing silent.
- install_url_hijack: onInstalled opens editingnews.com/tutorial (3rd-party redirect on install).
- localhost:5035 host permission exposes local network services to extension code.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for TikTok; confirmed_owner=false; not verified publisher for brand.
- install_url_hijack crx onInstalled redirects to https://editingnews.com/tutorial; +2.0 Webstore per rubric.
- cookies_high_perm_with_tiktok_host manifest cookies permission + *://tiktok.com/* host access; session hijack surface.
- privacy_policy_not_scoped api scope_extension=false, data_collection=false, third_party_silence=true; privacy score +9.0+1.0.
- localhost_host_permission manifest http://localhost:5035/* grants access to local services; unusual for a video-enhancer.
- no_developer_name store developer_name is empty; +1.0 reputation per rubric.
- verified_publisher store verified_publisher=true; -3.0 reputation, but capped at -1.0 due to brand impersonation context.
- js_external_hosts crx 7 external hosts including t.me (Telegram), emscripten.org, react.dev alongside tiktok/editingnews.
Permissions Breakdown
- storage low Standard local storage; low risk alone.
- tabs medium Can enumerate open tabs and URLs.
- scripting high Allows programmatic script injection into pages.
- activeTab low Scoped to user-activated tab; limited blast radius.
- downloads medium Can initiate file downloads without user confirmation.
- cookies high Can read/write cookies; paired with tiktok.com host access = session hijack risk.
- alarms low Scheduling only; minimal direct harm.
- *://tiktok.com/* high Full host access to TikTok; combined with cookies enables session theft.
- *://*.tiktok.com/* high Covers all TikTok subdomains including auth endpoints.
- *://tiktokcdn.com/* medium CDN access needed for media downloads; lower risk than auth domains.
- *://*.tiktokcdn.com/* medium CDN subdomain sweep; justified for video download function.
- *://byteoversea.com/* medium ByteDance infrastructure domain; access broader than strictly needed.
- *://*.byteoversea.com/* medium ByteDance subdomain sweep; extends reach to backend APIs.
- http://localhost:5035/* medium Localhost access; potential to probe local services or companion app.
- https://v2.editingnews.com/* medium Developer backend; data sent to third-party server.
- *://*.editingnews.com/* medium Broad dev-domain sweep including any future subdomain.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.50
Webstore5.50
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
70b21db6fd4c…
Force block
— not fired
Score recovered
no
Elapsed
27.4s