Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

UET Tag Helper (by Microsoft Advertising)

naijndjklgmffmpembnkfbcjbognokbf
Risk Score
4.29
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 100,000
Rating 4.5
Last updated 2026-01-24 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer BrowserExtensions@microsoft.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); 4 medium jQuery CVEs unfixed.
  • No CSP present (MV3 but null content_security_policy); new Function() in two files amplifies CVE risk.
  • Privacy policy fetch failed — cannot confirm scope or data-collection disclosures for this extension.
  • Broad host permissions (http://*/ + https://*/) combined with scripting and webRequest cover all sites.
  • jquery@2.1.4 + no CSP triggers v2 calibration jquery/<3.5+no-CSP Code Quality amplifier.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1 — still at vulnerable version.
  • high_cve_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
  • medium_cves_jquery crx jquery@2.1.4 carries 4 medium CVEs (XSS); fixed_in 3.4.0–3.5.0.
  • no_csp manifest content_security_policy is null; MV3 default is strict but no explicit policy set — amplifies CVE exploitability.
  • function_constructor_findings crx new Function() used in aria.telemetry.min.js and logHelper.js — dynamic code gen increases CVE exploit surface.
  • broad_host_permissions manifest host_permissions: http://*/ and https://*/ with content_scripts matching all URLs.
  • privacy_policy_fetch_failed api Privacy policy URL http://aka.ms/privacy returned HTTPError; classification fields all false — scored as fetched==false.
  • microsoft_recognized_org store Microsoft Corporation developer; is_featured_by_google=true; brand_mention confirmed_owner=true; no impersonation.

CVE Exposures (6)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS
CVE-2019-11358 jquery@2.1.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab low User-gesture-scoped tab access; limited blast radius.
  • downloads medium Can save files to disk; moderate risk if misused.
  • tabs medium Can read URLs/titles of all open tabs.
  • webNavigation medium Monitors page navigation across all sites.
  • webRequest high Observes all HTTP requests across all URLs (read-only but broad).
  • scripting high Injects scripts into pages; combined with broad host access is high-risk.
  • storage low Local extension storage; no direct exfil risk.
  • http://*/ high Broad host permission covering all HTTP sites.
  • https://*/ high Broad host permission covering all HTTPS sites.

Pillar Scores

Permissions6.50
Reputation2.00
Network4.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure9.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA a13224d5b776…
Force block — not fired
Score recovered no
Elapsed 31.4s