Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sticky Notes New Tab

llokcoejiedkbcibibhhefbcmdhcahdd
Risk Score
6.67
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 901
Rating 4.6
Last updated 2023-11-21 (31 months ago)
Manifest version MV3
CSP present ❌ no
Developer newtabthemescontact@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); no CSP amplifies risk.
  • New tab override replaces every new tab; uninstall URL hijacks to 3rd-party newtabthemebuilder.com.
  • Privacy policy is generic Google account policy — does not scope to this extension at all (admitted data collection + 3rd-party sharing).
  • Extension is 31 months stale (MV3 but no updates since Nov 2023); CVEs unfixed.
  • Free-webmail developer (gmail) with no developer name and no verified publisher badge.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical ACE); fixed in 1.12.1. No CSP present — v2 ×1.5 amplifier applies.
  • newtab_override manifest chrome_url_overrides.newtab set to index.html — replaces every new tab page.
  • uninstall_url_hijack crx uninstall_url_target=https://newtabthemebuilder.com/feedback — 3rd-party redirect on uninstall (+3.0 Webstore).
  • install_url_hijack crx onInstalled opens ./index.html — install URL hijack signal (+2.0 Webstore).
  • generic_privacy_policy store Privacy policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • stale_extension store 31 months since last update; CVEs present and unfixed. v2 triple-stale fingerprint +2.0 Webstore.
  • free_webmail_no_dev_name store Developer email newtabthemescontact@gmail.com; developer_name empty; no verified publisher — Reputation floor 7.5.
  • dom_xss_sink_no_csp crx innerHTML userctrl sink in main.js with csp_present=false and CVEs present → +2.0 Code Quality (FIX B).

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • chrome_url_overrides.newtab medium Replaces new tab page — high-visibility hijack surface, scored as MEDIUM override permission.

Pillar Scores

Permissions3.00
Reputation7.50
Network2.00
Webstore9.50
Maintenance8.50
Privacy10.00
Code Quality2.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA 8ab740b6622d…
Force block — not fired
Score recovered no
Elapsed 27.6s