Uncanny Cookie Clicker
mmmdenlpgbgmeofmdkhimecmkcgabgno
Risk Score
6.21
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.4.1 (Arbitrary Code Execution); unfixed for years.
- Extension not updated in 39 months — stale libraries with known critical/high CVEs will never be patched.
- Privacy policy is Google's generic account policy (scope_extension=false, admits data collection + 3rd-party sharing) — not scoped to this extension.
- No CSP + jQuery@1.10.2 with three moderate XSS CVEs + innerHTML sink creates real DOM-XSS attack surface.
- Free-webmail developer (gmail), no verified publisher, no business domain — unverifiable accountability.
Evidence
- critical_cve_bundled crx underscore@1.4.1 carries CVE-2021-23358 (critical, Arbitrary Code Execution); fixed_in 1.12.1.
- high_cve_bundled crx underscore@1.4.1 carries CVE-2026-27601 (high, DoS via unlimited recursion); fixed_in 1.13.8.
- moderate_cves_jquery crx jquery@1.10.2 carries 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11023, CVE-2015-9251).
- no_csp_with_cves manifest content_security_policy is null on MV3 extension with CVE-bearing DOM-manipulation libs and innerHTML sink.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated March 2023 (39 months). CVE-laden libraries will never be patched at this cadence.
- free_webmail_dev store Developer email builtinnya@gmail.com; no business domain, no verified publisher badge.
- function_constructor_in_libs crx new Function() found in underscore.js (template engine) and jquery.js (JSON parse fallback).
CVE Exposures (5)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.4.1 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.4.1 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
| CVE-2019-11358 | jquery@1.10.2 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.10.2 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.10.2 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- tabs medium Can read tab URLs and metadata; moderate risk for an entertainment helper.
- storage low Persistent local state; low risk.
- notifications low Can surface desktop notifications; low risk.
- host: orteil.dashnet.org/cookieclicker/ low Scoped exclusively to the Cookie Clicker game domain; matches stated function.
Pillar Scores
Permissions1.30
Reputation6.50
Network2.00
Webstore1.00
Maintenance10.00
Privacy10.00
Code Quality5.50
CVE Exposure9.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA
b454caa99e6b…
Force block
— not fired
Score recovered
no
Elapsed
32.4s