Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TikTok Enhancer - Editing News & Re:TikTok

kflflcpnnkojolplllfgcjobkgjmpdon
Risk Score
4.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 20,000
Rating 4.0
Last updated 2026-06-10
Manifest version MV3
CSP present ✅ yes
Developer contact@editingnews.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension names TikTok in title but confirmed_owner=false; not verified for TikTok brand.
  • cookies + scripting + full tiktok.com host access enables TikTok session/credential exfiltration.
  • Privacy policy not scoped to this extension; data_collection unaddressed, third_party_sharing silent.
  • install_url_hijack: onInstalled opens editingnews.com/tutorial (3rd-party redirect on install).
  • localhost:5035 host permission exposes local network services to extension code.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for TikTok; confirmed_owner=false; not verified publisher for brand.
  • install_url_hijack crx onInstalled redirects to https://editingnews.com/tutorial; +2.0 Webstore per rubric.
  • cookies_high_perm_with_tiktok_host manifest cookies permission + *://tiktok.com/* host access; session hijack surface.
  • privacy_policy_not_scoped api scope_extension=false, data_collection=false, third_party_silence=true; privacy score +9.0+1.0.
  • localhost_host_permission manifest http://localhost:5035/* grants access to local services; unusual for a video-enhancer.
  • no_developer_name store developer_name is empty; +1.0 reputation per rubric.
  • verified_publisher store verified_publisher=true; -3.0 reputation, but capped at -1.0 due to brand impersonation context.
  • js_external_hosts crx 7 external hosts including t.me (Telegram), emscripten.org, react.dev alongside tiktok/editingnews.

Permissions Breakdown

  • storage low Standard local storage; low risk alone.
  • tabs medium Can enumerate open tabs and URLs.
  • scripting high Allows programmatic script injection into pages.
  • activeTab low Scoped to user-activated tab; limited blast radius.
  • downloads medium Can initiate file downloads without user confirmation.
  • cookies high Can read/write cookies; paired with tiktok.com host access = session hijack risk.
  • alarms low Scheduling only; minimal direct harm.
  • *://tiktok.com/* high Full host access to TikTok; combined with cookies enables session theft.
  • *://*.tiktok.com/* high Covers all TikTok subdomains including auth endpoints.
  • *://tiktokcdn.com/* medium CDN access needed for media downloads; lower risk than auth domains.
  • *://*.tiktokcdn.com/* medium CDN subdomain sweep; justified for video download function.
  • *://byteoversea.com/* medium ByteDance infrastructure domain; access broader than strictly needed.
  • *://*.byteoversea.com/* medium ByteDance subdomain sweep; extends reach to backend APIs.
  • http://localhost:5035/* medium Localhost access; potential to probe local services or companion app.
  • https://v2.editingnews.com/* medium Developer backend; data sent to third-party server.
  • *://*.editingnews.com/* medium Broad dev-domain sweep including any future subdomain.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.50
Webstore5.50
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA 70b21db6fd4c…
Force block — not fired
Score recovered no
Elapsed 27.4s