Loom – Screen Recorder & Screen Capture
liecbddmkiiihnedobmlmillhodjkdmb
Risk Score
4.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 (arbitrary code execution) in bundled underscore@1.8.3; not updated to fixed version 1.12.1.
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: admits broad data sharing without extension-specific scoping.
- cookies + <all_urls> + webRequest + scripting combination grants near-total access to all browsing sessions.
- new Function() constructor used in 4 injected content-script files increases attack surface if input taint reaches those paths.
- 8M installs amplify blast radius of any future supply-chain compromise or unpatched CVE exploitation.
Evidence
- verified_publisher+featured store Verified publisher badge and featured by Google; reputation floor 2.0 applied; discount capped at -1.0 per v3.5 invariant 0c (cve_findings_raw non-empty).
- cve_critical_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed_in 1.12.1 not met.
- cve_high_underscore crx underscore@1.8.3 bundles CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8 not met.
- privacy_policy_scope_gap api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- broad_host_high_perms manifest <all_urls> with cookies+webRequest+scripting; justified-broad discount applied for Screenshot category.
- function_constructor_x4 crx new Function() pattern in 4 injected JS files (recordConsoleEvents*, recordNetworkEvents*).
- atlassian_external_hosts crx JS references atlassian/loom-owned hosts (cdn.loom.com, www.atlassian.com, support.atlassian.com); no bad hosts detected.
- no_developer_name store developer_name is empty string; email domain loom.com resolves and is not throwaway.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- system.memory low Read system memory stats; needed for screen recording performance monitoring.
- activeTab low Access current tab on user action only; limited scope.
- alarms low Schedule background tasks; low standalone risk.
- contextMenus low Add right-click menu items; low risk.
- cookies high Read/write cookies across origins; paired with <all_urls> host access raises risk significantly.
- desktopCapture high Capture screen, window, or tab content; core function but high capability.
- scripting high Inject scripts into pages; broad with <all_urls> host access.
- storage low Local extension storage; low risk.
- system.cpu low Read CPU stats; low risk.
- system.display low Query display info for capture; low risk.
- tabCapture high Capture tab audio/video stream; core recording function but high capability.
- webNavigation medium Observe navigation events; used for integration triggers.
- webRequest high Observe all network requests; combined with <all_urls> is high risk.
- <all_urls> high Broad host access enabling cookies+scripting+webRequest across all sites.
Pillar Scores
Permissions5.50
Reputation2.00
Network2.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure7.00
Scoring History
| sssiedna7987472dp727562726963xsx | 4.08 | Medium | review | 2026-09-02 |
| sssiednb89a6501dp727562726963xsx | 4.08 | Medium | review | 2026-08-25 |
| xx pfsssiedxm$"sssiedx | 3.02 | Low | review | 2026-08-20 |
| %27fsssiedxm sssiedx | 4.04 | Medium | review | 2026-08-20 |
| 4.04 | Medium | block | 2026-08-20 | |
| <fsssiedxm | 4.14 | Medium | review | 2026-08-20 |
| <fsssiedxm$"sssiedx | 3.63 | Low | review | 2026-08-20 |
| <fsssiedx{"sssiedx | 3.33 | Low | review | 2026-08-20 |
| <fsssiedxh$'sssiedx | 4.13 | Medium | review | 2026-08-20 |
| <fsssiedxa"sssiedx | 4.04 | Medium | review | 2026-08-13 |
| <fsssiedxa$"sssiedx | 4.04 | Medium | review | 2026-08-13 |
| %22fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.20 | Medium | review | 2026-08-07 |
| 'fsssiedxa$'sssiedx | 3.64 | Low | review | 2026-08-07 |
| fsssiedxa$"sssiedx | 2.97 | Low | review | 2026-08-07 |
| <fsssiedxa'sssiedx | 2.93 | Low | review | 2026-08-07 |
| <fsssiedxa$'sssiedx | 3.54 | Low | review | 2026-08-07 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 2.97 | Low | review | 2026-08-07 |
| <fsssiedxa"sssiedx | 2.97 | Low | review | 2026-08-07 |
| fsssiedxa<sssiedx | 4.09 | Medium | review | 2026-08-07 |
| sssieddrubricxsx | 3.02 | Low | review | 2026-08-04 |
| v3.6 | 4.07 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA
0711f67af30b…
Force block
— not fired
Score recovered
no
Elapsed
33.8s