Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Portugal National Team – FIFA World Cup 2026 Squad Top 20 Wallpapers

moniepcmaabbodpinonaakcpjfcjajhi
Risk Score
5.62
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 553
Rating
Last updated 2026-06-02 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer eminearsiz0@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override combined with uninstall-URL hijack to gameograf.com reveals monetization-shell pattern.
  • Privacy policy is Google's own generic policy — not scoped to this extension; admits data collection and third-party sharing.
  • Three medium-severity jQuery CVEs (1.9.1) bundled with no CSP — XSS amplifier active.
  • Free-webmail developer (eminearsiz0@gmail.com) with no verified publisher status and no business domain.
  • 12 external JS hosts including social/ad-adjacent domains; no CSP on MV3 provides no script-src enforcement.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL → https://gameograf.com/?utm_source=ovkas — 3rd-party monetization redirect on uninstall.
  • newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab hijacked, search perm present.
  • generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy — Google's policy, not extension-scoped; data_collection+third_party_sharing=true.
  • jquery_cves crx jquery@1.9.1 carries 3 medium XSS CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in 3.5.0.
  • no_csp manifest content_security_policy is null on MV3; no script-src enforcement despite 12 external hosts and CVE-bearing jQuery.
  • free_webmail_dev store Developer email eminearsiz0@gmail.com — free webmail, no verified publisher, no business website.
  • install_url_hijack manifest onInstalled opens index.html — internal redirect; lower risk but confirms shell pattern.
  • external_hosts_breadth crx 12 external JS hosts: gameograf.com, crazycraftz.com, jqueryui.com, popper.js.org among others.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • search medium Allows reading/overriding search queries; elevated in a NewTab shell.
  • topSites medium Exposes user's most-visited sites; privacy-sensitive in an ad-monetization context.
  • unlimitedStorage low Allows unlimited local storage; low standalone risk.
  • storage low Standard key-value storage; low risk.
  • chrome_url_overrides.newtab high Replaces every new tab with extension page; high-reach monetization surface.

Pillar Scores

Permissions4.30
Reputation7.50
Network4.00
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure3.75

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:27
Listing SHA 6ba071e43453…
Force block — not fired
Score recovered no
Elapsed