Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Take Webpage Screenshots Entirely - FireShot

mcbpblocgmgfnpjjppndjkmgjaogfceg
Risk Score
4.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 3,000,000
Rating 4.8
Last updated 2026-05-24 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer contacts@getfireshot.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic policy trigger).
  • nativeMessaging with unrecognized publisher allows arbitrary native-app code execution on host OS.
  • jQuery 3.3.1 bundled with 3 medium-severity CVEs (XSS); not updated to fixed version 3.5.0.
  • Dynamic script loading (script_src_dynamic) and Function constructor found in code; elevated injection risk.
  • 10 distinct external JS hosts contacted including screenshot-program.com; broader than expected for a screenshot tool.

Evidence

  • native_messaging_unrecognized_publisher crx nativeMessaging declared; native_messaging_check.publisher_recognized == false. Allows OS-level code execution.
  • privacy_policy_generic_with_third_party_sharing crx Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar.
  • cve_jquery_3_3_1_moderate_x3 crx jquery@3.3.1 has CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (moderate XSS); fixed_in 3.5.0.
  • code_script_src_dynamic crx scripts/enc/fsWorker.js creates dynamic <script src=> element; enables remote code load in worker context.
  • code_function_constructor crx scripts/vue/vue-index.js uses new Function(); elevated eval-equivalent risk.
  • external_hosts_diverse crx 10 distinct external JS hosts: api.inboxsdk.com, screenshot-program.com, ssl.getfireshot.com and 7 others.
  • verified_publisher_featured store Verified publisher + Google Featured badge; discounts applied but capped due to privacy policy concerns.
  • description_promise_mismatch store Description promises recording but lacks tabCapture/desktopCapture permissions.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Stores extension settings locally; minimal risk.
  • alarms low Schedules tasks; low standalone risk.
  • scripting medium Injects scripts into tabs; necessary for screenshot capture but elevates capability.
  • activeTab medium Accesses current tab content on user action; scoped but grants page access.
  • nativeMessaging high Communicates with native companion app; publisher not recognized, high-impact channel.
  • contextMenus low Adds right-click menu items; no data access.

Pillar Scores

Permissions5.50
Reputation2.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure3.00

Scoring History

sssieddrubricxsx 4.37 Medium review 2026-08-09
v3.6 4.54 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA 51fa09fecb1d…
Force block — not fired
Score recovered no
Elapsed 31.0s