AudD® Music Recognition
lhhohkfofnfbnildpdhhjeeenapeceei
Risk Score
4.44
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- tabCapture permission records browser audio from any tab — sensitive data captured without clear retention policy.
- jQuery 3.3.1 bundles 3 medium XSS CVEs (fixed in 3.5.0); extension not updated in 17 months.
- Privacy policy does not scope to this extension and omits data retention; third-party sharing not addressed.
- identity.email reads user email; no policy disclosure on how it is stored or shared.
- 12 external JS hosts in CSP fingerprint including social/CDN domains; broader network surface than API-only would require.
Evidence
- tabCapture_permission manifest tabCapture declared — records tab audio; core function but high data sensitivity.
- jquery_3_cves crx jquery@3.3.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed in 3.5.0.
- privacy_policy_scope api Policy fetched but scope_extension=false, data_collection=false, retention=false; generic and inadequate.
- stale_17mo store Last updated Jan 2, 2025 — 17 months without update despite unpatched CVEs.
- content_scripts_all_urls manifest content_scripts_matches=[*://*/*] — runs on every site, broadening CVE exposure surface.
- no_developer_name store developer_name is empty string; reduces accountability.
- is_featured_google store Extension carries Google Featured badge — mild trust signal.
- no_bad_hosts api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- identity low OAuth sign-in; no broad scope declared.
- identity.email medium Reads user email address via Google OAuth.
- storage low Local key-value storage; standard.
- unlimitedStorage low Extended local storage; low abuse risk alone.
- background medium Persistent background context; keeps extension alive.
- activeTab low Scoped to current tab on user gesture.
- tabCapture medium Captures audio/video from active tab; music-recognition function justifies but raises data sensitivity.
- notifications low Display notifications; minimal standalone risk.
Pillar Scores
Permissions3.50
Reputation5.50
Network3.00
Webstore1.50
Maintenance6.00
Privacy9.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA
e9f37126f2fc…
Force block
— not fired
Score recovered
no
Elapsed
25.1s