Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Telegram Video Downloader - TVD

lbfjfamhbgbaldijoohdfbdfkgmpdbni
Risk Score
4.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VideoDownloader
Installs 10,000
Rating 4.5
Last updated 2026-06-04
Manifest version MV3
CSP present ❌ no
Developer m41m41.a@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection + third-party sharing without scoping to this extension → maximum privacy risk.
  • Brand impersonation of 'Telegram' by unverified gmail developer with no business identity.
  • Install and uninstall URL hijacks redirect user browser to third-party destinations.
  • Free-webmail developer, no name — low accountability; higher risk of future transfer or abandonment.
  • Permission-description mismatch: claims download capability but lacks 'downloads' permission.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; 'telegram' brand used in name; confirmed_owner=false; developer is gmail user.
  • privacy_policy_generic crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D clause → +10.0 privacy.
  • install_url_hijack crx onInstalled opens https://web.telegram.org/k — navigates user browser on install.
  • uninstall_url_hijack crx setUninstallURL points to Google Forms survey; 3rd-party redirect on uninstall.
  • free_webmail_dev_no_name store developer_email=m41m41.a@gmail.com; developer_name empty; no business domain.
  • description_permission_mismatch store Promises 'download' but lacks 'downloads' permission per description_promise.mismatches.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; partially mitigates reputation risk.
  • no_csp manifest content_security_policy=null on MV3; MV3 default strict but noted alongside external hosts.

Permissions Breakdown

  • storage low Stores local extension state; low standalone risk.
  • activeTab low Access to current tab on user action only; scoped.
  • host: https://web.telegram.org/* medium Content-script access to Telegram web; matches stated function.
  • content_script: https://extensionpay.com/* medium Injects into payment processor domain; billing surface but plausibly for monetization.

Pillar Scores

Permissions2.00
Reputation7.50
Network2.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA 1a41b73cab64…
Force block — not fired
Score recovered no
Elapsed 23.6s