Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

NaturalReader - AI Text to Speech

kohfgcgbkjodfcfkcackpagifgbcmimk
Risk Score
5.26
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Accessibility
Installs 900,000
Rating 4.2
Last updated 2026-08-29 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer sales@naturalreaders.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@1.9.1 bundled with 3 moderate CVEs (XSS); fixed version is 3.5.0 — far behind current.
  • Dynamic <script src> injection in content script running on <all_urls> enables remote code execution risk.
  • Privacy policy fetched but does not scope to this extension or disclose what data is collected (+9.0 privacy score).
  • Multiple innerHTML DOM-XSS sinks in injected scripts active on every page visited.
  • brand_mention flags 'google' impersonation; no developer name listed and not a verified publisher.

Evidence

  • jquery@1.9.1 with 3 moderate CVEs present in bundled bootstrap crx jquery 1.9.1 detected via inline-marker in bootstrap.bundle.min.js; CVE-2015-9251, CVE-2019-11358, CVE-2020-11023 unpatched.
  • script_src_dynamic in content script with <all_urls> crx nr-ext-dom-detector.js dynamically appends <script src=...> tags on every visited page.
  • Privacy policy not scoped to extension; data_collection=false but scope_extension=false api PDF policy at naturalreaders.com/media/privacy2.pdf does not reference extension or specify collection scope.
  • No developer name; brand impersonation flag on 'google' store developer_name is empty; brand_mention.is_impersonation=true for 'google'; not a verified publisher.
  • <all_urls> host permission with content_scripts on all sites manifest content_scripts_matches includes <all_urls>; scripting+webNavigation+tabs compound the broad reach.
  • 12 distinct external JS hosts including 7 AWS API Gateway endpoints crx js_external_hosts has 12 entries; multiple opaque execute-api.us-east-1.amazonaws.com subdomains contacted.
  • function_constructor in 4 background/injected files crx new Function() used in amplify-config.js, ocr.js, online-tts.js, injected/amplify-config.js.
  • Featured by Google; MV3; CSP present; no bad/affiliate/monetization hosts store is_featured_by_google=true, MV3, CSP script-src self, threat_intel all clean — mitigating factors.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • scripting medium Can inject scripts into pages; moderate risk especially combined with <all_urls>.
  • activeTab low Temporary access to active tab only; low standalone risk.
  • contextMenus low Adds right-click menu items; minimal risk.
  • storage low Local extension storage; low risk.
  • tts low Text-to-speech output only; core function, low risk.
  • ttsEngine low Provides TTS engine; core function, low risk.
  • webNavigation medium Observes navigation events across all URLs; surveillance potential.
  • tabs medium Access to tab URLs and metadata across browsing session.
  • <all_urls> (host_permission) high Content scripts inject into every page; broad access amplifies all other risks.

Pillar Scores

Permissions5.50
Reputation5.50
Network3.50
Webstore3.50
Maintenance1.50
Privacy9.00
Code Quality7.00
CVE Exposure3.00

Scoring History

sssiedn9f538212dp727562726963xsx 4.84 Medium review 2026-09-07
sssiedn79d6dae0dp727562726963xsx 5.00 Medium review 2026-09-06
<fsssiedxi xx psssiedx 4.73 Medium review 2026-08-17
<fsssiedxa$"sssiedx 5.59 Medium review 2026-08-17
%27fsssiedxa$'sssiedx 4.93 Medium review 2026-08-15
fsssiedxa<sssiedx 4.85 Medium review 2026-08-15
<fsssiedxa sssiedx 5.17 Medium review 2026-07-29
fsssiedx<sssiedx 4.76 Medium review 2026-07-29
sssieddrubricxsx 4.93 Medium review 2026-07-29
v3.6 5.26 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA 5d6bd478a5ee…
Force block — not fired
Score recovered no
Elapsed 38.1s