Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Awesome Screen Recorder & Screenshot

nlipoenfbbikpbjkfpfillcgkoblgpmj
Risk Score
4.92
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 3,000,000
Rating 4.7
Last updated 2026-08-03
Manifest version MV3
CSP present ✅ yes
Developer care@awesomescreenshot.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true: admits broad data collection without scoping to this extension.
  • cookies + <all_urls> + scripting: high-capability combo enabling cross-site data access and script injection on every visited page.
  • desktopCapture + tabCapture: can silently record full desktop and any browser tab.
  • jquery@3.4.0 bundled with CVE-2020-11022/11023 (XSS); multiple function_constructor and innerHTML DOM-XSS sinks in content scripts.
  • No developer name listed; privacy policy does not scope data handling to this extension despite confirmed third-party sharing.

Evidence

  • cookies+<all_urls>+scripting manifest High-capability triple: cookies, scripting, <all_urls> host_permissions and content_scripts on http://*/* https://*/*.
  • privacy_policy_scope_miss crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
  • cve_jquery_3.4.0 crx jquery@3.4.0 bundles CVE-2020-11022 and CVE-2020-11023 (moderate XSS); fixed_in 3.5.0.
  • function_constructor_multi crx new Function() constructor found in 8 bundle files including pageWorld.bundle.js with non-trivial wrapper usage.
  • dom_innerHTML_sinks crx innerHTML user-controlled sinks in 4 bundle files including gmailContent.bundle.js and content.bundle.js.
  • sandbox_csp_remote_scripts manifest Sandbox CSP allows script-src ssl.google-analytics.com, www.google-analytics.com, connect.facebook.net, platform.twitter.com.
  • verified_publisher+featured store verified_publisher=true, is_featured_by_google=true; reputation floor applied at 2.0.
  • monetization_telemetry_only crx monetization_hits: Google Analytics only (telemetry tier); no affiliate or bad hosts.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.0 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata across all tabs.
  • power low Prevents device sleep; low privacy impact.
  • storage low Local extension data storage.
  • unlimitedStorage low Extended local storage for recordings/screenshots.
  • desktopCapture high Can capture full desktop screen content.
  • tabCapture high Can capture audio/video of any tab.
  • cookies high Read/write cookies across origins; paired with <all_urls>.
  • activeTab low Scoped to user-activated tab only.
  • contextMenus low Adds right-click menu items.
  • scripting high Can inject scripts into pages; paired with <all_urls>.
  • offscreen low Offscreen document for media processing.
  • alarms low Background scheduling; minimal risk.
  • <all_urls> high Broad host access enabling script injection and cookie access on all sites.

Pillar Scores

Permissions7.00
Reputation2.00
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure3.00

Scoring History

<fsssiedxa"sssiedx 4.39 Medium review 2026-08-19
<fsssiedxa&#x27;sssiedx 4.03 Medium review 2026-08-19
<fsssiedxa 3.06 Low review 2026-08-13
<fsssiedxa&#x22;sssiedx 3.01 Low review 2026-08-13
<fsssiedxa'sssiedx 3.01 Low review 2026-08-13
<fsssiedxa$'sssiedx 3.06 Low review 2026-08-13
<fsssiedxa xx psssiedx 4.04 Medium review 2026-08-13
fsssiedxa<sssiedx 4.14 Medium review 2026-08-13
<fsssiedxa$"sssiedx 4.03 Medium review 2026-08-09
fsssiedx<sssiedx 4.05 Medium review 2026-08-09
sssieddrubricxsx 4.19 Medium review 2026-07-31
v3.6 4.92 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA afbd66f5a953…
Force block — not fired
Score recovered no
Elapsed 34.9s