Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sound Booster - increase volume up

nmigaijibiabddkkmjhlehchpmgbokfj
Risk Score
4.26
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Accessibility
Installs 2,000,000
Rating 4.5
Last updated 2026-08-18
Manifest version MV3
CSP present ❌ no
Developer alnortcc12@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing without scoping to this extension — scored at max privacy risk.
  • Two outdated jQuery versions (3.2.1, 3.4.1) bundled with 5 moderate XSS CVEs, none fixed.
  • Free-webmail developer (gmail) with no developer name raises accountability concerns.
  • tabCapture + <all_urls> content scripts gives extension access to audio of every tab on every site.
  • jquery@<3.5 + no CSP combo amplifies XSS CVE exploitability (v2e rule applies).

Evidence

  • privacy_policy_admits_collection_and_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
  • bundled_vulnerable_jquery crx jquery@3.4.1 (CVE-2020-11022, CVE-2020-11023) and jquery@3.2.1 (CVE-2019-11358, +2) — 5 moderate CVEs unfixed.
  • no_csp_plus_jquery_below_3.5 crx csp_present=false + jquery<3.5 triggers v2e +2.0 Code Quality penalty and CVE ×1.5 amplifier.
  • gmail_developer_no_name store developer_email=alnortcc12@gmail.com, developer_name empty; free-webmail dev with no business identity.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discounts applied but capped per invariant 0c not triggered.
  • host_permissions_all_urls_with_content_scripts manifest <all_urls> in both host_permissions and content_scripts_matches; broad reach for audio booster.
  • external_hosts crx js_external_hosts: chrome.google.com, microsoftedge.microsoft.com, sound-ultimate.com; 2 countries (CA, US).
  • large_install_base store 2,000,000 installs with rating 4.5; high blast radius if extension compromised or sold.

CVE Exposures (5)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Access to tab metadata; needed for audio capture coordination.
  • tabCapture high Captures tab audio/video stream; core function but high capability.
  • storage low Local settings persistence; standard low-risk.
  • system.display low Read display info; minimal risk for UI layout.
  • offscreen medium Off-screen document for audio processing; enables background execution.
  • <all_urls> (host_permissions) high Content scripts injected on all URLs; broad reach paired with tabCapture.

Pillar Scores

Permissions5.00
Reputation4.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure5.25

Scoring History

<fsssiedxa sssiedx 4.20 Medium review 2026-08-19
%22fsssiedxa<sssiedx 4.12 Medium review 2026-08-19
%22fsssiedxa$'sssiedx 4.61 Medium review 2026-08-19
%27fsssiedxa"sssiedx 4.07 Medium review 2026-08-19
fsssiedxa'sssiedx 4.23 Medium review 2026-08-19
xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.22 Medium review 2026-08-14
fsssiedxa&#x22;sssiedx 4.22 Medium review 2026-08-14
<fsssiedxa xx psssiedx 4.30 Medium review 2026-08-13
<fsssiedxa"sssiedx 4.73 Medium review 2026-08-10
<fsssiedxa&#x27;sssiedx 3.63 Low review 2026-08-10
<fsssiedxa&#x22;sssiedx 4.97 Medium review 2026-08-06
xx pfsssiedxasssiedx 5.21 Medium review 2026-08-06
%22fsssiedxa xx psssiedx 4.30 Medium review 2026-08-06
"fsssiedxa$"sssiedx 4.18 Medium review 2026-08-06
&#x22;fsssiedxa'sssiedx 4.26 Medium review 2026-08-06
4.11 Medium review 2026-08-06
fsssiedxa$'sssiedx 4.14 Medium review 2026-08-06
<fsssiedxa'sssiedx 4.66 Medium review 2026-08-01
<fsssiedxa$"sssiedx 4.59 Medium review 2026-08-01
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 5.29 Medium review 2026-08-01
<fsssiedxa$'sssiedx 4.83 Medium review 2026-08-01
fsssiedxa<sssiedx 4.52 Medium review 2026-08-01
xx pfsssiedxa<sssiedx 5.52 Medium review 2026-08-01
fsssiedxa"sssiedx 5.14 Medium review 2026-08-01
fsssiedxa&#x27;sssiedx 4.54 Medium review 2026-08-01
fsssiedxa$"sssiedx 4.39 Medium review 2026-08-01
sssieddrubricxsx 4.23 Medium review 2026-08-01
fsssiedxa xx psssiedx 4.02 Medium review 2026-07-28
v3.6 4.26 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA b3895f508402…
Force block — not fired
Score recovered no
Elapsed 29.0s