Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tanks Game

kmiidcaojgeepjlccoalkdimgpfnbagj
Risk Score
4.58
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 63
Rating 5.0
Last updated 2026-04-14 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer viktornadiezhdin@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (arbitrary code execution) in bundled underscore@1.8.3 — well below fixed version 1.12.1
  • eval_user_input in opus.wasm.js: direct eval() of variable enabling arbitrary code execution
  • Privacy policy hosted on cdn.cloudapi.stream is not scoped to this extension and admits third-party sharing
  • Uninstall URL hijack flagged; install_url_hijack opens popup/index.html — redirect hooks present
  • CSP allows unsafe-eval and unsafe-inline on script-src, undermining XSS protections despite CSP presence

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code execution); fixed in 1.12.1
  • high_cve_bundled_lib crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8
  • eval_user_input crx Direct eval() of funcstr in popup/scripts/opus.wasm.js — code quality HIGH risk
  • dom_sink_innerhtml crx innerHTML from userAgent in supportcheck.js; CSP has unsafe-eval so XSS mitigations weak
  • unsafe_csp manifest CSP allows 'unsafe-eval' and 'unsafe-inline' on script-src for both extension_pages and sandbox
  • privacy_policy_inadequate store Policy on cdn.cloudapi.stream: scope_extension=false, data_collection=false, third_party_sharing=true
  • uninstall_url_hijack crx uninstall_url_hijack=true and install_url_hijack=true flagged in manifest analysis
  • free_webmail_dev_no_name store Developer email viktornadiezhdin@gmail.com with no developer_name listed

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Pillar Scores

Permissions0.00
Reputation5.00
Network2.00
Webstore5.00
Maintenance1.50
Privacy9.00
Code Quality6.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:26
Listing SHA af4bc82eb6b4…
Force block — not fired
Score recovered no
Elapsed