Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

OurTab

mchacgmgddefeohkjobefhihbadocneh
Risk Score
6.28
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 4
Rating
Last updated 2025-08-19 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer weijancc@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); high CVE also present — far below fixed versions.
  • No CSP + critical/high CVE in DOM-manipulation lib (underscore) triggers ×1.5 CVE amplifier; CVE pillar capped at 10.
  • new Function() constructor used in Vue template compilation with no CSP; innerHTML sink also present — code execution surface.
  • NewTab override with 12 external JS hosts (CN+US) and no CSP; privacy policy not scoped to this extension.
  • Free-webmail developer (weijancc@gmail.com), unverified publisher, privacy policy lacks scope/retention disclosure.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Also CVE-2026-27601 (high, DoS).
  • no_csp_with_cve_dom_lib crx csp_present=false AND critical CVE in underscore (DOM-manipulation lib); CVE pillar ×1.5 amplifier applied.
  • function_constructor_usage crx new Function() in 2 JS files; +2.5 code quality per rubric (function_constructor signal).
  • dom_sink_no_csp crx innerHTML from variable + csp_present=false + CVE present → +2.0 code quality (FIX B).
  • newtab_override manifest chrome_url_overrides.newtab replaces new tab page; +2.0 webstore (newtab override with monetization shape).
  • 12_external_js_hosts crx 12 distinct external JS hosts including CN domains (cdn.vgn.cn, vgn.cn, inftab.com, cikeee.com, fkkq.net).
  • privacy_policy_not_scoped store Policy fetched; scope_extension=false, data_collection=false → +9.0 privacy per v3 FIX A.
  • free_webmail_developer store Developer email weijancc@gmail.com; no verified publisher badge; reputation pillar elevated.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • *://*.google.com/* medium Host permission scoped to google.com; limited but allows reading Google pages.
  • chrome_url_overrides.newtab medium Replaces new tab page — high-visibility real estate, monetization surface.

Pillar Scores

Permissions3.00
Reputation6.50
Network2.00
Webstore4.50
Maintenance3.50
Privacy9.00
Code Quality7.00
CVE Exposure10.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:20
Listing SHA dbc006ef0cbc…
Force block — not fired
Score recovered no
Elapsed