Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Browser Security Plus

mhkgegcmcapcgmnnloigolapjkajgfmd
Risk Score
6.64
Risk Level: High
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category Security
Installs 1,000,000
Rating 1.6
Last updated 2026-06-15
Manifest version MV3
CSP present ❌ no
Developer support-extensions@manageengine.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • CRITICAL permission stack: management + nativeMessaging + contentSettings + webRequest + scripting + <all_urls> — complete browser control with unrecognized native host.
  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — D clause triggers +10.0 privacy score.
  • Brand impersonation flag: brand_mention.is_impersonation==true for 'google' while developer is not verified owner — reputation penalty applied.
  • No developer name listed; rating of 1.6 on 1M installs is a strong negative quality signal.

Evidence

  • high_permission_stack manifest management, nativeMessaging, webRequest, privacy, contentSettings, scripting all declared with <all_urls> host permission.
  • native_messaging_unrecognized_publisher crx has_native_messaging=true, publisher_recognized=false → +3.0 permissions per rule (15).
  • privacy_policy_generic_with_sharing api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • brand_impersonation store brand_mention.is_impersonation=true for 'google'; confirmed_owner=false; not verified_publisher → +2.0 reputation.
  • low_rating_high_installs store Rating 1.6 on 1,000,000 installs is a strong negative signal; +1.0 reputation if >= 50 ratings assumed.
  • dom_xss_sink_no_csp crx innerHTML from variable in contentScript.js; csp_present=false triggers FIX B escalation to +2.0 code quality.
  • no_developer_name store developer_name is empty string; partial +1.0 reputation penalty for missing 'Offered by' identity.
  • verified_publisher_present store verified_publisher=true applies -3.0 reputation discount; 0c cap not triggered (domain resolves, no CVEs, months_since_update=0, no monetization hits).

Permissions Breakdown

  • management high Can enumerate, enable/disable, or uninstall other extensions — extreme capability.
  • webRequest high Can observe all HTTP/S traffic across all URLs (paired with <all_urls>).
  • nativeMessaging high Bridges to a native host app; publisher_recognized==false amplifies risk.
  • privacy high Can read/write browser privacy settings (network prediction, safe browsing, etc.).
  • contentSettings high Can override per-site cookie, JS, camera, mic, and plugin permissions.
  • downloads medium Can initiate and monitor file downloads.
  • scripting high Programmatic script injection into any page via <all_urls> host permission.
  • tabs medium Access to tab URLs, titles, and navigation state.
  • webNavigation medium Monitors all navigation events across all URLs.
  • <all_urls> (host) high Broad host access amplifies every HIGH permission by ×1.2.

Pillar Scores

Permissions8.50
Reputation5.50
Network2.00
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

v3.6 6.64 High block 2026-06-16
v3.4-rev 5.55 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA e2c55a088f46…
Force block 🚫 fired
Score recovered no
Elapsed 29.2s