OurTab
mchacgmgddefeohkjobefhihbadocneh
Risk Score
6.28
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); high CVE also present — far below fixed versions.
- No CSP + critical/high CVE in DOM-manipulation lib (underscore) triggers ×1.5 CVE amplifier; CVE pillar capped at 10.
- new Function() constructor used in Vue template compilation with no CSP; innerHTML sink also present — code execution surface.
- NewTab override with 12 external JS hosts (CN+US) and no CSP; privacy policy not scoped to this extension.
- Free-webmail developer (weijancc@gmail.com), unverified publisher, privacy policy lacks scope/retention disclosure.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Also CVE-2026-27601 (high, DoS).
- no_csp_with_cve_dom_lib crx csp_present=false AND critical CVE in underscore (DOM-manipulation lib); CVE pillar ×1.5 amplifier applied.
- function_constructor_usage crx new Function() in 2 JS files; +2.5 code quality per rubric (function_constructor signal).
- dom_sink_no_csp crx innerHTML from variable + csp_present=false + CVE present → +2.0 code quality (FIX B).
- newtab_override manifest chrome_url_overrides.newtab replaces new tab page; +2.0 webstore (newtab override with monetization shape).
- 12_external_js_hosts crx 12 distinct external JS hosts including CN domains (cdn.vgn.cn, vgn.cn, inftab.com, cikeee.com, fkkq.net).
- privacy_policy_not_scoped store Policy fetched; scope_extension=false, data_collection=false → +9.0 privacy per v3 FIX A.
- free_webmail_developer store Developer email weijancc@gmail.com; no verified publisher badge; reputation pillar elevated.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- *://*.google.com/* medium Host permission scoped to google.com; limited but allows reading Google pages.
- chrome_url_overrides.newtab medium Replaces new tab page — high-visibility real estate, monetization surface.
Pillar Scores
Permissions3.00
Reputation6.50
Network2.00
Webstore4.50
Maintenance3.50
Privacy9.00
Code Quality7.00
CVE Exposure10.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:20
Listing SHA
dbc006ef0cbc…
Force block
— not fired
Score recovered
no
Elapsed
—