Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Loom – Screen Recorder & Screen Capture

liecbddmkiiihnedobmlmillhodjkdmb
Risk Score
4.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 8,000,000
Rating 4.6
Last updated 2026-08-31 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@loom.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 (arbitrary code execution) in bundled underscore@1.8.3; not updated to fixed version 1.12.1.
  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: admits broad data sharing without extension-specific scoping.
  • cookies + <all_urls> + webRequest + scripting combination grants near-total access to all browsing sessions.
  • new Function() constructor used in 4 injected content-script files increases attack surface if input taint reaches those paths.
  • 8M installs amplify blast radius of any future supply-chain compromise or unpatched CVE exploitation.

Evidence

  • verified_publisher+featured store Verified publisher badge and featured by Google; reputation floor 2.0 applied; discount capped at -1.0 per v3.5 invariant 0c (cve_findings_raw non-empty).
  • cve_critical_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed_in 1.12.1 not met.
  • cve_high_underscore crx underscore@1.8.3 bundles CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8 not met.
  • privacy_policy_scope_gap api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • broad_host_high_perms manifest <all_urls> with cookies+webRequest+scripting; justified-broad discount applied for Screenshot category.
  • function_constructor_x4 crx new Function() pattern in 4 injected JS files (recordConsoleEvents*, recordNetworkEvents*).
  • atlassian_external_hosts crx JS references atlassian/loom-owned hosts (cdn.loom.com, www.atlassian.com, support.atlassian.com); no bad hosts detected.
  • no_developer_name store developer_name is empty string; email domain loom.com resolves and is not throwaway.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • system.memory low Read system memory stats; needed for screen recording performance monitoring.
  • activeTab low Access current tab on user action only; limited scope.
  • alarms low Schedule background tasks; low standalone risk.
  • contextMenus low Add right-click menu items; low risk.
  • cookies high Read/write cookies across origins; paired with <all_urls> host access raises risk significantly.
  • desktopCapture high Capture screen, window, or tab content; core function but high capability.
  • scripting high Inject scripts into pages; broad with <all_urls> host access.
  • storage low Local extension storage; low risk.
  • system.cpu low Read CPU stats; low risk.
  • system.display low Query display info for capture; low risk.
  • tabCapture high Capture tab audio/video stream; core recording function but high capability.
  • webNavigation medium Observe navigation events; used for integration triggers.
  • webRequest high Observe all network requests; combined with <all_urls> is high risk.
  • <all_urls> high Broad host access enabling cookies+scripting+webRequest across all sites.

Pillar Scores

Permissions5.50
Reputation2.00
Network2.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure7.00

Scoring History

sssiedna7987472dp727562726963xsx 4.08 Medium review 2026-09-02
sssiednb89a6501dp727562726963xsx 4.08 Medium review 2026-08-25
xx pfsssiedxm$"sssiedx 3.02 Low review 2026-08-20
%27fsssiedxm sssiedx 4.04 Medium review 2026-08-20
4.04 Medium block 2026-08-20
<fsssiedxm 4.14 Medium review 2026-08-20
<fsssiedxm$"sssiedx 3.63 Low review 2026-08-20
<fsssiedx{"sssiedx 3.33 Low review 2026-08-20
<fsssiedxh$'sssiedx 4.13 Medium review 2026-08-20
<fsssiedxa&#x22;sssiedx 4.04 Medium review 2026-08-13
<fsssiedxa$"sssiedx 4.04 Medium review 2026-08-13
%22fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.20 Medium review 2026-08-07
&#x27;fsssiedxa$'sssiedx 3.64 Low review 2026-08-07
fsssiedxa$"sssiedx 2.97 Low review 2026-08-07
<fsssiedxa'sssiedx 2.93 Low review 2026-08-07
<fsssiedxa$'sssiedx 3.54 Low review 2026-08-07
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 2.97 Low review 2026-08-07
<fsssiedxa"sssiedx 2.97 Low review 2026-08-07
fsssiedxa<sssiedx 4.09 Medium review 2026-08-07
sssieddrubricxsx 3.02 Low review 2026-08-04
v3.6 4.07 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA 0711f67af30b…
Force block — not fired
Score recovered no
Elapsed 33.8s