Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AudD® Music Recognition

lhhohkfofnfbnildpdhhjeeenapeceei
Risk Score
4.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 40,000
Rating 3.6
Last updated 2025-01-02 (17 months ago)
Manifest version MV3
CSP present ✅ yes
Developer hello@audd.io
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • tabCapture permission records browser audio from any tab — sensitive data captured without clear retention policy.
  • jQuery 3.3.1 bundles 3 medium XSS CVEs (fixed in 3.5.0); extension not updated in 17 months.
  • Privacy policy does not scope to this extension and omits data retention; third-party sharing not addressed.
  • identity.email reads user email; no policy disclosure on how it is stored or shared.
  • 12 external JS hosts in CSP fingerprint including social/CDN domains; broader network surface than API-only would require.

Evidence

  • tabCapture_permission manifest tabCapture declared — records tab audio; core function but high data sensitivity.
  • jquery_3_cves crx jquery@3.3.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed in 3.5.0.
  • privacy_policy_scope api Policy fetched but scope_extension=false, data_collection=false, retention=false; generic and inadequate.
  • stale_17mo store Last updated Jan 2, 2025 — 17 months without update despite unpatched CVEs.
  • content_scripts_all_urls manifest content_scripts_matches=[*://*/*] — runs on every site, broadening CVE exposure surface.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • is_featured_google store Extension carries Google Featured badge — mild trust signal.
  • no_bad_hosts api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • identity low OAuth sign-in; no broad scope declared.
  • identity.email medium Reads user email address via Google OAuth.
  • storage low Local key-value storage; standard.
  • unlimitedStorage low Extended local storage; low abuse risk alone.
  • background medium Persistent background context; keeps extension alive.
  • activeTab low Scoped to current tab on user gesture.
  • tabCapture medium Captures audio/video from active tab; music-recognition function justifies but raises data sensitivity.
  • notifications low Display notifications; minimal standalone risk.

Pillar Scores

Permissions3.50
Reputation5.50
Network3.00
Webstore1.50
Maintenance6.00
Privacy9.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA e9f37126f2fc…
Force block — not fired
Score recovered no
Elapsed 25.1s