MaxAI: Ask AI anything as you browse (GPT, Gemini, Claude, Grok, etc.)
mhnlakgilnojmhinhkckjpncpbhabphi
Risk Score
7.00
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- Critical CVE in bundled underscore@1.8.3 (arbitrary code execution) with no CSP and DOM-XSS sinks present — amplified risk.
- No CSP + scripting+<all_urls>+declarativeNetRequestWithHostAccess enables full page interception and JS injection across all sites.
- Uninstall URL hijack configured; brand impersonation (Gemini/Claude) without confirmed ownership by those vendors.
- management permission allows enumerating and disabling other installed extensions — rare and high-impact capability.
Evidence
- cve_critical_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical ACE); fixed in 1.12.1. No CSP present — CVE amplifier ×1.5 applies.
- no_csp_mv3 manifest content_security_policy is null; MV3 default restricts eval but DOM sinks and Function() constructor still active.
- function_constructor_code_finding crx new Function() constructor found in chunks/BS5W3VC5.js — dynamic code execution path.
- dom_xss_sinks_no_csp crx 3 innerHTML-from-variable findings across background.js and chunks; no CSP to mitigate DOM-XSS.
- management_permission manifest management permission declared — can enumerate/disable other extensions. Unusual for an AI assistant.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() set; target URL not captured but hijack confirmed.
- brand_impersonation store brands_mentioned: [claude, gemini]; confirmed_owner: false; is_impersonation: true; verified_publisher does not negate.
- privacy_policy_third_party_sharing api Policy fetched, scoped, data_collection=true, third_party_sharing=true, retention=true. Third-party sharing disclosed.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- tabs medium Access to tab URLs/titles; moderate risk with broad host access.
- scripting high Can inject JS into any page via <all_urls>; high capability.
- storage low Local data storage; low standalone risk.
- management high Can list/disable other extensions; significant privilege.
- contextMenus low Adds right-click menu items; low risk.
- clipboardRead medium Can read clipboard contents; privacy risk.
- clipboardWrite medium Can write to clipboard; moderate risk.
- declarativeNetRequestWithHostAccess high Can modify/block network requests on all URLs.
- <all_urls> (host) high Full access to all sites; broadens every other permission.
Pillar Scores
Permissions8.50
Reputation4.00
Network5.50
Webstore6.50
Maintenance0.00
Privacy1.00
Code Quality7.00
CVE Exposure7.00
Scoring History
| v3.6 | 7.00 | High | block | 2026-06-16 |
| v3.4-rev | 5.34 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA
c5d82ecf4222…
Force block
— not fired
Score recovered
no
Elapsed
34.7s