Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MaxAI: Ask AI anything as you browse (GPT, Gemini, Claude, Grok, etc.)

mhnlakgilnojmhinhkckjpncpbhabphi
Risk Score
7.00
Risk Level: High
Recommendation: 🚫 BLOCK
Category AI
Installs 700,000
Rating 4.7
Last updated 2026-06-03
Manifest version MV3
CSP present ❌ no
Developer hello@maxai.me
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
  • Critical CVE in bundled underscore@1.8.3 (arbitrary code execution) with no CSP and DOM-XSS sinks present — amplified risk.
  • No CSP + scripting+<all_urls>+declarativeNetRequestWithHostAccess enables full page interception and JS injection across all sites.
  • Uninstall URL hijack configured; brand impersonation (Gemini/Claude) without confirmed ownership by those vendors.
  • management permission allows enumerating and disabling other installed extensions — rare and high-impact capability.

Evidence

  • cve_critical_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical ACE); fixed in 1.12.1. No CSP present — CVE amplifier ×1.5 applies.
  • no_csp_mv3 manifest content_security_policy is null; MV3 default restricts eval but DOM sinks and Function() constructor still active.
  • function_constructor_code_finding crx new Function() constructor found in chunks/BS5W3VC5.js — dynamic code execution path.
  • dom_xss_sinks_no_csp crx 3 innerHTML-from-variable findings across background.js and chunks; no CSP to mitigate DOM-XSS.
  • management_permission manifest management permission declared — can enumerate/disable other extensions. Unusual for an AI assistant.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() set; target URL not captured but hijack confirmed.
  • brand_impersonation store brands_mentioned: [claude, gemini]; confirmed_owner: false; is_impersonation: true; verified_publisher does not negate.
  • privacy_policy_third_party_sharing api Policy fetched, scoped, data_collection=true, third_party_sharing=true, retention=true. Third-party sharing disclosed.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Access to tab URLs/titles; moderate risk with broad host access.
  • scripting high Can inject JS into any page via <all_urls>; high capability.
  • storage low Local data storage; low standalone risk.
  • management high Can list/disable other extensions; significant privilege.
  • contextMenus low Adds right-click menu items; low risk.
  • clipboardRead medium Can read clipboard contents; privacy risk.
  • clipboardWrite medium Can write to clipboard; moderate risk.
  • declarativeNetRequestWithHostAccess high Can modify/block network requests on all URLs.
  • <all_urls> (host) high Full access to all sites; broadens every other permission.

Pillar Scores

Permissions8.50
Reputation4.00
Network5.50
Webstore6.50
Maintenance0.00
Privacy1.00
Code Quality7.00
CVE Exposure7.00

Scoring History

v3.6 7.00 High block 2026-06-16
v3.4-rev 5.34 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA c5d82ecf4222…
Force block — not fired
Score recovered no
Elapsed 34.7s