Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Infinite Dashboard - New Tab like no other

meffljleomgifbbcffejnmhjagncfpbd
Risk Score
6.12
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 100,000
Rating 4.4
Last updated 2026-04-09 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer quantiennambo@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection + 3rd-party sharing but is not scoped to this extension — scores max privacy risk.
  • Three moderate jQuery CVEs (XSS) unfixed; no CSP amplifies DOM-XSS sinks across newtab.js, search-helper.js, preview-maker.js.
  • NewTab override + <all_urls> content scripts give the extension reach into every page and new tab with scripting capability.
  • Developer email is free webmail (gmail) with no verified business identity; uninstall URL hijack to infinitetab.com.
  • Geo-diverse JS hosts (CA/NL/RU/US, 4 countries) and 12 external JS hosts increase supply-chain attack surface.

Evidence

  • privacy_policy_admits_collection_sharing_no_scope store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule → +10.0 privacy.
  • jquery_3.3.1_three_moderate_cves crx CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 in jquery@3.3.1; fixed_in 3.5.0; no CSP amplifier applies.
  • dom_xss_sinks_no_csp crx 3 innerHTML sinks in newtab.js, search-helper.js, preview-maker.js; csp_present=false → each scores +2.0 (FIX B).
  • newtab_override_all_urls manifest chrome_url_overrides.newtab + host_permissions <all_urls> + content_scripts on all URLs.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://infinitetab.com/uninstall.html (+3.0 webstore).
  • install_url_hijack crx onInstalled opens /newtab.html?url= (+2.0 webstore).
  • free_webmail_dev_no_name store developer_email=quantiennambo@gmail.com; developer_name empty; free webmail dev identity.
  • geo_diversity_4_countries crx JS hosts span CA, NL, RU, US (4 countries); category=NewTab → +1.5 network.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata across all open tabs.
  • storage low Local key-value storage for extension state.
  • search medium Can read and interact with the browser's search engine.
  • unlimitedStorage low Removes storage quota; low direct harm.
  • topSites medium Reads user's most-visited sites — mild privacy signal.
  • scripting medium Can inject scripts into pages; elevated with <all_urls> host permission.
  • contextMenus low Adds items to right-click menu; minimal risk alone.
  • <all_urls> (host) high Content scripts and scripting API can reach every site the user visits.
  • chrome_url_overrides.newtab medium Replaces every new-tab page; high reach, monetization risk.

Pillar Scores

Permissions7.50
Reputation4.00
Network4.50
Webstore7.50
Maintenance1.50
Privacy10.00
Code Quality5.00
CVE Exposure4.50

Scoring History

sssiedn00ad3a70dp727562726963xsx 4.82 Medium review 2026-08-30
v3.6 6.12 High review 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:56
Listing SHA b0d1e3c9e049…
Force block — not fired
Score recovered no
Elapsed