Void - The most customizable portal to the web
mfgnpbldopkbgphddaifenkolikoepbe
Risk Score
7.47
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- Search provider + newtab + homepage override: complete browser UI hijack to askvoid.com.
- management permission allows disabling other extensions silently.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
- Uninstall and install URL hijacks open third-party pages; monetization funnel pattern.
Evidence
- search_provider_override + newtab_override + homepage_override manifest chrome_settings_overrides sets default search to askvoid.com and homepage; newtab also overridden.
- uninstall_url_hijack + install_url_hijack crx Uninstall redirects to askvoid.com/bye; install opens askvoid.com/welcome — monetization funnel.
- management permission manifest Can enumerate and disable other installed extensions — highly privileged.
- privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 via rule D.
- search_redirect_probe api is_direct_provider=false; search routes through askvoid.com but no external ad-tech redirect detected.
- install_perm_anomaly store 624 installs, has_high_tier_permission=true, small_install_high_perm=true, tail_attack_surface=true.
- dom_sink_innerhtml_userctrl + csp_present=false crx innerHTML sink present with no CSP — elevated XSS risk under v3 FIX B.
- months_since_update=20 + verified_publisher store Stale >18mo triggers invariant 0c: verified-publisher discount capped at -1.0.
Permissions Breakdown
- storage low Stores extension settings locally.
- alarms low Schedules background tasks; low direct harm.
- declarativeNetRequest medium Can block/redirect network requests; medium risk without full webRequest.
- notifications low Can push notifications; limited harm alone.
- management high Can enumerate, enable, disable other extensions — high privilege.
- history medium Full browsing history read access; significant privacy exposure.
- host_permissions: https://*/* high Broad host access paired with content scripts on all URLs; high reach.
- content_scripts: <all_urls> high Script injection into every page; combined with management is critical surface.
- chrome_url_overrides.newtab medium Replaces new tab page; monetization surface.
- chrome_settings_overrides.search_provider high Sets default search engine to askvoid.com; high search-hijack risk.
- chrome_settings_overrides.homepage medium Overrides homepage to askvoid.com.
Pillar Scores
Permissions8.50
Reputation4.00
Network4.00
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:19
Listing SHA
86d24ae30e3c…
Force block
— not fired
Score recovered
no
Elapsed
—