UET Tag Helper (by Microsoft Advertising)
naijndjklgmffmpembnkfbcjbognokbf
Risk Score
4.29
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); 4 medium jQuery CVEs unfixed.
- No CSP present (MV3 but null content_security_policy); new Function() in two files amplifies CVE risk.
- Privacy policy fetch failed — cannot confirm scope or data-collection disclosures for this extension.
- Broad host permissions (http://*/ + https://*/) combined with scripting and webRequest cover all sites.
- jquery@2.1.4 + no CSP triggers v2 calibration jquery/<3.5+no-CSP Code Quality amplifier.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1 — still at vulnerable version.
- high_cve_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
- medium_cves_jquery crx jquery@2.1.4 carries 4 medium CVEs (XSS); fixed_in 3.4.0–3.5.0.
- no_csp manifest content_security_policy is null; MV3 default is strict but no explicit policy set — amplifies CVE exploitability.
- function_constructor_findings crx new Function() used in aria.telemetry.min.js and logHelper.js — dynamic code gen increases CVE exploit surface.
- broad_host_permissions manifest host_permissions: http://*/ and https://*/ with content_scripts matching all URLs.
- privacy_policy_fetch_failed api Privacy policy URL http://aka.ms/privacy returned HTTPError; classification fields all false — scored as fetched==false.
- microsoft_recognized_org store Microsoft Corporation developer; is_featured_by_google=true; brand_mention confirmed_owner=true; no impersonation.
CVE Exposures (6)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
| CVE-2019-11358 | jquery@2.1.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- activeTab low User-gesture-scoped tab access; limited blast radius.
- downloads medium Can save files to disk; moderate risk if misused.
- tabs medium Can read URLs/titles of all open tabs.
- webNavigation medium Monitors page navigation across all sites.
- webRequest high Observes all HTTP requests across all URLs (read-only but broad).
- scripting high Injects scripts into pages; combined with broad host access is high-risk.
- storage low Local extension storage; no direct exfil risk.
- http://*/ high Broad host permission covering all HTTP sites.
- https://*/ high Broad host permission covering all HTTPS sites.
Pillar Scores
Permissions6.50
Reputation2.00
Network4.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure9.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
a13224d5b776…
Force block
— not fired
Score recovered
no
Elapsed
31.4s