Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Free VPN for Chrome - VPN Proxy VeePN

majdfhpaihoncoakbjgbdhglocklcgno
Risk Score
6.03
Risk Level: High
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category VPN
Installs 14,000,000
Rating 4.5
Last updated 2026-08-25
Manifest version MV3
CSP present ✅ yes
Developer support@veepn.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true → admits data collection/sharing without scoping to this extension (max privacy score).
  • Extremely high-capability permission stack: proxy + cookies + webRequest + privacy + management + <all_urls> — can intercept, reroute, and harvest all browser traffic.
  • Uninstall URL hijack detected; extension registers a third-party URL on uninstall.
  • management permission allows this extension to enumerate and disable other installed extensions.

Evidence

  • permissions_high_capability manifest proxy+cookies+webRequest+privacy+management+<all_urls> — full traffic interception and extension control stack.
  • privacy_policy_generic api scope_extension=false, data_collection=true, third_party_sharing=true → admits broad sharing without extension scope.
  • uninstall_url_hijack crx uninstall_url_hijack=true; redirects user to third-party URL on uninstall.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts capped due to monetization_hits.
  • monetization_hits crx Google Analytics telemetry endpoint present in js_external_hosts.
  • broad_external_hosts crx 12 external hosts including split-tool.com, AWS Lambda URL, amplitude.com, fake-veepn.com.
  • dom_xss_sinks crx Two innerHTML-from-variable findings in bundled JS; CSP is present so elevated-severity rule does not fully trigger.
  • high_install_count store 14,000,000 installs; blast radius is very large if any compromise occurs.

Permissions Breakdown

  • storage low Stores settings locally; minimal risk.
  • proxy high Can route all browser traffic through arbitrary servers.
  • tabs medium Can read tab URLs and titles across all sites.
  • cookies high Access to all cookies; paired with <all_urls> this is critical.
  • notifications low Push notifications; low standalone risk.
  • webRequest high Intercept and observe all network requests across all URLs.
  • webRequestAuthProvider high Can supply auth credentials for network requests.
  • privacy high Can alter Chrome privacy/network settings (proxy, DoH, etc.).
  • management high Can enumerate, disable, or uninstall other extensions.
  • <all_urls> (host) high Full host access; compounds cookies, proxy, webRequest risk.

Pillar Scores

Permissions8.00
Reputation2.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality1.00
CVE Exposure0.00

Scoring History

sssiednfb9f1611dp727562726963xsx 5.84 Medium block 2026-08-30
<fsssiedxi$'sssiedx 5.43 Medium block 2026-08-17
<fsssiedxa sssiedx 3.77 Low block 2026-08-17
fsssiedx<sssiedx 3.77 Low block 2026-08-17
<fsssiedxa xx psssiedx 6.47 High block 2026-08-13
<fsssiedxa$'sssiedx 5.46 Medium block 2026-08-13
<fsssiedxa"sssiedx 5.37 Medium block 2026-08-13
<fsssiedxa&#x27;sssiedx 5.09 Medium block 2026-08-13
<fsssiedxa$"sssiedx 5.72 Medium block 2026-08-13
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 5.60 Medium block 2026-08-13
<fsssiedxa'sssiedx 5.01 Medium block 2026-08-13
<fsssiedxa 5.08 Medium block 2026-08-13
fsssiedxa<sssiedx 5.03 Medium block 2026-08-13
fsssiedxcfdsaxax><!--></ScRiPt>asddsssiedx 3.72 Low block 2026-07-28
sssieddrubricxsx 5.24 Medium block 2026-07-28
v3.6 6.03 High block 2026-06-16
v3.4-rev 4.22 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA 7ad198bd3ff5…
Force block 🚫 fired
Score recovered no
Elapsed 28.2s