Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screencastify - Screen Video Recorder

mmeijimgabbpbgpdklnllpncmdofkcpn
Risk Score
5.24
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 4,000,000
Rating 3.9
Last updated 2026-07-21 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@screencastify.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • underscore@1.8.3 bundles critical CVE-2021-23358 (Arbitrary Code Execution) and high CVE-2026-27601 (DoS); not updated past fixed versions.
  • Broad host permissions (<all_urls> + scripting) allow script injection into every page visited by 6M users.
  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing true — admits broad data sharing without scoping to this extension.
  • 5 external JS hosts (unpkg.com, github.com, emscripten.org, vuejs.org, v3-migration.vuejs.org) create supply-chain exposure.
  • No developer display name; rating 3.9 is below positive threshold for a 6M-install extension.

Evidence

  • critical_cve crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical); fixed in 1.12.1 — bundled version unfixed.
  • high_cve crx underscore@1.8.3 has CVE-2026-27601 (DoS, high); fixed in 1.13.8 — bundled version unfixed.
  • broad_host_permissions manifest <all_urls> + *://*/* paired with scripting permission enables page-wide script injection.
  • privacy_policy_scope_mismatch api Policy fetched (28k chars) but scope_extension=false, data_collection=true, third_party_sharing=true.
  • external_js_hosts crx 5 distinct external hosts referenced: unpkg.com, github.com, emscripten.org, vuejs.org, v3-migration.vuejs.org.
  • no_developer_name store developer_name is empty string; reduces accountability signal.
  • featured_by_google store is_featured_by_google=true; partially mitigates reputation concerns.
  • content_scripts_google_drive_mail manifest Content scripts run on mail.google.com, drive.google.com, outlook.live.com — sensitive data surfaces.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2020-36632 flat@unknown critical 1.6.2 flat vulnerable to Prototype Pollution
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • alarms low Scheduling only, no data access.
  • storage low Local extension data persistence.
  • tabs medium Can read tab URLs and titles across sessions.
  • activeTab medium Access to current tab content on user action.
  • offscreen low Offscreen document for media processing; low standalone risk.
  • scripting high Injects scripts into pages; combined with <all_urls> is high risk.
  • unlimitedStorage low Storage quota only; no extra data access.
  • tabCapture high Captures audio/video of any tab — core screen recorder function but high capability.
  • desktopCapture high Captures entire desktop screen and audio.
  • webNavigation medium Observes navigation events across tabs.
  • notifications low Display notifications only.
  • system.display low Read display metadata for recording config.
  • <all_urls> high Broad host access enabling scripting on every site.
  • *://*/* high Redundant broad host permission amplifying <all_urls> reach.

Pillar Scores

Permissions6.50
Reputation4.50
Network3.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure7.00

Scoring History

%22fsssiedxa sssiedx 5.10 Medium review 2026-08-14
&#x22;fsssiedxa'sssiedx 4.44 Medium review 2026-08-14
fsssiedxa&#x22;sssiedx 4.02 Medium review 2026-08-14
"fsssiedxa xx psssiedx 4.47 Medium review 2026-08-08
%27fsssiedxa$"sssiedx 5.23 Medium block 2026-08-08
5.21 Medium review 2026-08-08
fsssiedxa$'sssiedx 5.37 Medium block 2026-08-08
&#x22;fsssiedxgfdsaxax><!--></ScRiPt>asddsssiedx 5.32 Medium review 2026-08-07
<fsssiedxf&#x27;sssiedx 5.14 Medium review 2026-08-07
<fsssiedx{$"sssiedx 4.15 Medium review 2026-08-07
<fsssiedxi$'sssiedx 5.34 Medium review 2026-08-07
<fsssiedx{ xx psssiedx 5.24 Medium review 2026-08-04
xx pfsssiedxi$'sssiedx 4.37 Medium review 2026-08-04
'fsssiedxi$"sssiedx 5.92 Medium review 2026-08-04
&#x22;fsssiedxi&#x27;sssiedx 4.13 Medium review 2026-08-04
fsssiedxi<sssiedx 5.62 Medium review 2026-08-04
<fsssiedxf$"sssiedx 5.26 Medium review 2026-08-04
<fsssiedxi'sssiedx 5.34 Medium review 2026-08-04
<fsssiedxa&#x22;sssiedx 3.51 Low review 2026-08-04
<fsssiedxi$"sssiedx 5.73 Medium block 2026-07-29
<fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx 5.13 Medium review 2026-07-29
fsssiedx<sssiedx 5.24 Medium review 2026-07-29
xx pfsssiedxh$"sssiedx 5.16 Medium review 2026-07-29
%27fsssiedxh"sssiedx 4.56 Medium review 2026-07-29
&#x27;fsssiedxh$'sssiedx 5.62 Medium review 2026-07-29
<fsssiedxh sssiedx 5.61 Medium review 2026-07-29
<fsssiedxh$"sssiedx 5.14 Medium review 2026-07-29
%22fsssiedxa$"sssiedx 6.88 High block 2026-07-28
fsssiedxa$"sssiedx 5.27 Medium review 2026-07-28
<fsssiedxa xx psssiedx 5.37 Medium review 2026-07-28
<fsssiedxa'sssiedx 4.08 Medium review 2026-07-28
<fsssiedxa$"sssiedx 4.12 Medium review 2026-07-28
<fsssiedxa$'sssiedx 5.34 Medium review 2026-07-28
<fsssiedxa&#x27;sssiedx 5.06 Medium review 2026-07-28
<fsssiedxa"sssiedx 3.63 Low review 2026-07-28
fsssiedxa<sssiedx 5.54 Medium review 2026-07-28
fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 5.18 Medium review 2026-07-28
sssieddrubricxsx 5.27 Medium review 2026-07-28
v3.6 5.24 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA c33bfb44e056…
Force block — not fired
Score recovered no
Elapsed 27.1s