Infinite Dashboard - New Tab like no other
meffljleomgifbbcffejnmhjagncfpbd
Risk Score
6.12
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Privacy policy admits data collection + 3rd-party sharing but is not scoped to this extension — scores max privacy risk.
- Three moderate jQuery CVEs (XSS) unfixed; no CSP amplifies DOM-XSS sinks across newtab.js, search-helper.js, preview-maker.js.
- NewTab override + <all_urls> content scripts give the extension reach into every page and new tab with scripting capability.
- Developer email is free webmail (gmail) with no verified business identity; uninstall URL hijack to infinitetab.com.
- Geo-diverse JS hosts (CA/NL/RU/US, 4 countries) and 12 external JS hosts increase supply-chain attack surface.
Evidence
- privacy_policy_admits_collection_sharing_no_scope store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule → +10.0 privacy.
- jquery_3.3.1_three_moderate_cves crx CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 in jquery@3.3.1; fixed_in 3.5.0; no CSP amplifier applies.
- dom_xss_sinks_no_csp crx 3 innerHTML sinks in newtab.js, search-helper.js, preview-maker.js; csp_present=false → each scores +2.0 (FIX B).
- newtab_override_all_urls manifest chrome_url_overrides.newtab + host_permissions <all_urls> + content_scripts on all URLs.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://infinitetab.com/uninstall.html (+3.0 webstore).
- install_url_hijack crx onInstalled opens /newtab.html?url= (+2.0 webstore).
- free_webmail_dev_no_name store developer_email=quantiennambo@gmail.com; developer_name empty; free webmail dev identity.
- geo_diversity_4_countries crx JS hosts span CA, NL, RU, US (4 countries); category=NewTab → +1.5 network.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Access to tab URLs and metadata across all open tabs.
- storage low Local key-value storage for extension state.
- search medium Can read and interact with the browser's search engine.
- unlimitedStorage low Removes storage quota; low direct harm.
- topSites medium Reads user's most-visited sites — mild privacy signal.
- scripting medium Can inject scripts into pages; elevated with <all_urls> host permission.
- contextMenus low Adds items to right-click menu; minimal risk alone.
- <all_urls> (host) high Content scripts and scripting API can reach every site the user visits.
- chrome_url_overrides.newtab medium Replaces every new-tab page; high reach, monetization risk.
Pillar Scores
Permissions7.50
Reputation4.00
Network4.50
Webstore7.50
Maintenance1.50
Privacy10.00
Code Quality5.00
CVE Exposure4.50
Scoring History
| sssiedn00ad3a70dp727562726963xsx | 4.82 | Medium | review | 2026-08-30 |
| v3.6 | 6.12 | High | review | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:56
Listing SHA
b0d1e3c9e049…
Force block
— not fired
Score recovered
no
Elapsed
—