Adobe Photoshop
kjchkpkjpiloipaonppkmepcbhcncedo
Risk Score
4.73
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack declared; redirects user to unknown 3rd-party page on removal.
- No developer name listed despite high-profile Adobe branding — unverifiable publisher identity.
- Privacy policy fetch failed (ReadTimeout); effective privacy posture is unknown, scored worst-case.
- Content scripts on <all_urls> give broad page-read capability across all 800K users' browsing.
- chatgpt.com and github.com listed as JS external hosts — unexpected for a Photoshop imaging extension.
Evidence
- uninstall_url_hijack crx uninstall_url_hijack=true; target=null. Extension registers an uninstall redirect to a 3rd-party URL. Webstore +3.0.
- privacy_policy_fetch_failed crx privacy_policy_classification.fetched=false (ReadTimeout). Privacy pillar scored at maximum 10.0.
- no_developer_name store developer_name is empty string. Reputation +1.0 (no Offered By name).
- not_verified_publisher store verified_publisher=false for an extension claiming Adobe branding. No -3.0 verified discount.
- is_featured_by_google store is_featured_by_google=true. Reputation -2.0 featured discount applied.
- broad_host_permissions_and_content_scripts manifest host_permissions and content_scripts_matches both set to <all_urls>; runs on every site.
- unexpected_external_hosts crx js_external_hosts includes chatgpt.com, github.com, wxt.dev alongside adobe.com endpoints.
- ai_extension_page_content store Category AI + content scripts on <all_urls>; Webstore +2.5 AI/GenAI signal applied.
Permissions Breakdown
- storage low Local data persistence; low standalone risk.
- tabs medium Can read tab URLs and titles; moderate privacy surface.
- contextMenus low UI integration only; low risk.
- sidePanel low UI panel display; low risk.
- declarativeNetRequest medium Can redirect/block network requests without seeing content; moderate risk.
- <all_urls> (host_permissions) high Broad host access enables content-script injection on every site visited.
- <all_urls> (content_scripts_matches) high Scripts run on every page; high data-access reach amplified by <all_urls>.
Pillar Scores
Permissions6.50
Reputation4.00
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 13:52
Listing SHA
53bdc05fa433…
Force block
— not fired
Score recovered
no
Elapsed
—