Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Scrolling screenshot tool & screen capture

mfpiaehgjbbfednooihadalhehabhcjo
Risk Score
5.14
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 400,000
Rating 4.3
Last updated 2023-07-20 (35 months ago)
Manifest version MV3
CSP present ✅ yes
Developer care@awesomescreenshot.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false with data_collection+third_party_sharing=true — policy admits broad data collection without extension-specific scoping (+10.0 privacy).
  • Stale extension: 35 months since last update with known CVEs and broad host access — triple-stale fingerprint applies.
  • jQuery 3.4.0 bundled with 2 moderate XSS CVEs (CVE-2020-11022, CVE-2020-11023); fix available at 3.5.0.
  • Multiple innerHTML DOM-XSS sinks in content scripts running on all URLs, plus new Function() usage.
  • Uninstall URL redirects to awesomescreenshot.com domain; analytics hosts (Google Analytics) in CSP sandbox script-src.

Evidence

  • privacy_policy_admits_collection_and_sharing_no_extension_scope api scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • triple_stale_fingerprint store months_since_update=35 (>24mo), cve_findings_raw non-empty, manifest_version=3 → +2.0 webstore (v2 fix c).
  • cve_jquery_3.4.0_moderate_x2 crx CVE-2020-11022 + CVE-2020-11023 in jquery@3.4.0; fixed_in 3.5.0. 2 medium CVEs → +2.0 CVE pillar.
  • dom_sink_innerhtml_userctrl_multiple crx 6 innerHTML sink findings across content/bundle scripts; cve_findings_raw non-empty → each triggers +2.0 FIX B path.
  • function_constructor_usage crx new Function() constructor in annotate/feedback/option/dragresize bundles → +2.5 code quality.
  • uninstall_url_hijack manifest chrome.runtime setUninstallURL → awesomescreenshot.com/uninstall — developer-owned domain, not third-party.
  • monetization_hits_telemetry_only api Google Analytics (ssl/www.google-analytics.com) in threat_intel.monetization_hits; telemetry-tier only → +1.0 webstore.
  • verified_publisher_featured store verified_publisher=true + is_featured_by_google=true; discount capped at -1.0 due to monetization_hits (v3.5 rule E).

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.0 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Standard local data persistence.
  • unlimitedStorage low Needed to store large screenshots locally.
  • desktopCapture high Can capture full desktop/tab pixels including sensitive content.
  • activeTab medium Access to current tab content on user action.
  • scripting medium Can inject JS into pages; paired with <all_urls> broadens reach.
  • <all_urls> (host_permissions) high Content scripts run on every http/https page, wide attack surface.

Pillar Scores

Permissions5.50
Reputation2.00
Network3.50
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality5.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA 8d77bbbce38d…
Force block — not fired
Score recovered no
Elapsed 37.0s