Sound Booster - increase volume up
nmigaijibiabddkkmjhlehchpmgbokfj
Risk Score
4.26
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing without scoping to this extension — scored at max privacy risk.
- Two outdated jQuery versions (3.2.1, 3.4.1) bundled with 5 moderate XSS CVEs, none fixed.
- Free-webmail developer (gmail) with no developer name raises accountability concerns.
- tabCapture + <all_urls> content scripts gives extension access to audio of every tab on every site.
- jquery@<3.5 + no CSP combo amplifies XSS CVE exploitability (v2e rule applies).
Evidence
- privacy_policy_admits_collection_and_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
- bundled_vulnerable_jquery crx jquery@3.4.1 (CVE-2020-11022, CVE-2020-11023) and jquery@3.2.1 (CVE-2019-11358, +2) — 5 moderate CVEs unfixed.
- no_csp_plus_jquery_below_3.5 crx csp_present=false + jquery<3.5 triggers v2e +2.0 Code Quality penalty and CVE ×1.5 amplifier.
- gmail_developer_no_name store developer_email=alnortcc12@gmail.com, developer_name empty; free-webmail dev with no business identity.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discounts applied but capped per invariant 0c not triggered.
- host_permissions_all_urls_with_content_scripts manifest <all_urls> in both host_permissions and content_scripts_matches; broad reach for audio booster.
- external_hosts crx js_external_hosts: chrome.google.com, microsoftedge.microsoft.com, sound-ultimate.com; 2 countries (CA, US).
- large_install_base store 2,000,000 installs with rating 4.5; high blast radius if extension compromised or sold.
CVE Exposures (5)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Access to tab metadata; needed for audio capture coordination.
- tabCapture high Captures tab audio/video stream; core function but high capability.
- storage low Local settings persistence; standard low-risk.
- system.display low Read display info; minimal risk for UI layout.
- offscreen medium Off-screen document for audio processing; enables background execution.
- <all_urls> (host_permissions) high Content scripts injected on all URLs; broad reach paired with tabCapture.
Pillar Scores
Permissions5.00
Reputation4.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure5.25
Scoring History
| <fsssiedxa sssiedx | 4.20 | Medium | review | 2026-08-19 |
| %22fsssiedxa<sssiedx | 4.12 | Medium | review | 2026-08-19 |
| %22fsssiedxa$'sssiedx | 4.61 | Medium | review | 2026-08-19 |
| %27fsssiedxa"sssiedx | 4.07 | Medium | review | 2026-08-19 |
| fsssiedxa'sssiedx | 4.23 | Medium | review | 2026-08-19 |
| xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.22 | Medium | review | 2026-08-14 |
| fsssiedxa"sssiedx | 4.22 | Medium | review | 2026-08-14 |
| <fsssiedxa xx psssiedx | 4.30 | Medium | review | 2026-08-13 |
| <fsssiedxa"sssiedx | 4.73 | Medium | review | 2026-08-10 |
| <fsssiedxa'sssiedx | 3.63 | Low | review | 2026-08-10 |
| <fsssiedxa"sssiedx | 4.97 | Medium | review | 2026-08-06 |
| xx pfsssiedxasssiedx | 5.21 | Medium | review | 2026-08-06 |
| %22fsssiedxa xx psssiedx | 4.30 | Medium | review | 2026-08-06 |
| "fsssiedxa$"sssiedx | 4.18 | Medium | review | 2026-08-06 |
| "fsssiedxa'sssiedx | 4.26 | Medium | review | 2026-08-06 |
| 4.11 | Medium | review | 2026-08-06 | |
| fsssiedxa$'sssiedx | 4.14 | Medium | review | 2026-08-06 |
| <fsssiedxa'sssiedx | 4.66 | Medium | review | 2026-08-01 |
| <fsssiedxa$"sssiedx | 4.59 | Medium | review | 2026-08-01 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 5.29 | Medium | review | 2026-08-01 |
| <fsssiedxa$'sssiedx | 4.83 | Medium | review | 2026-08-01 |
| fsssiedxa<sssiedx | 4.52 | Medium | review | 2026-08-01 |
| xx pfsssiedxa<sssiedx | 5.52 | Medium | review | 2026-08-01 |
| fsssiedxa"sssiedx | 5.14 | Medium | review | 2026-08-01 |
| fsssiedxa'sssiedx | 4.54 | Medium | review | 2026-08-01 |
| fsssiedxa$"sssiedx | 4.39 | Medium | review | 2026-08-01 |
| sssieddrubricxsx | 4.23 | Medium | review | 2026-08-01 |
| fsssiedxa xx psssiedx | 4.02 | Medium | review | 2026-07-28 |
| v3.6 | 4.26 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA
b3895f508402…
Force block
— not fired
Score recovered
no
Elapsed
29.0s