Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Infinity New Tab (Pro)

nnnkddnnlpamobajfibfdgfnbcnkgngh
Risk Score
6.52
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 300,000
Rating 4.9
Last updated 2026-07-07 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer infinitynewtab@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: arbitrary code execution); not patched to fixed_in 1.12.1.
  • NewTab override contacts 4 distinct search engines (baidu, bing, google, yahoo) — multi-search-engine aggregator pattern (+2.5).
  • Privacy policy fetched but scope_extension==false while admitting data collection and third-party sharing — scores 10.0.
  • Free-webmail developer (gmail), no developer name listed — unverifiable identity raises accountability risk.
  • function_constructor new Function() used across 10+ files including Vue template compiler and debugger tracing paths.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Currently bundled at vulnerable version.
  • newtab_multi_search_engine crx search_engine_count=4 (baidu, bing, google, yahoo); NewTab+4 search engines triggers v3.5(C) +2.5.
  • privacy_policy_scope_missing_data_collected api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.0.
  • free_webmail_no_dev_name store Developer email infinitynewtab@gmail.com; developer_name empty. No verified publisher badge.
  • function_constructor_widespread crx new Function() found in 10+ files including template compiler and debugger-injection strings.
  • dom_xss_sink crx innerHTML assigned from variable in 4 files; csp_present=true but CVEs present → FIX B applies (+2.0).
  • newtab_override manifest chrome_url_overrides.newtab replaces every new tab for 300K users; high-reach capability.
  • js_external_hosts_cn_baidu crx 12 external JS hosts including baidu.com subdomains (CN-geolocated); country_count=2 (CN, US).

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • activeTab low Only accesses the active tab on user gesture; low ambient risk.
  • storage low Local data persistence for settings; standard for NewTab extensions.
  • unlimitedStorage low Allows larger local storage quota; no direct data-exfil vector.
  • offscreen low Creates offscreen documents; MV3 pattern, limited scope here.
  • background low Service worker background; declared redundantly in MV3 context.
  • search medium Can query and potentially redirect browser search; sensitive for NewTab.
  • chrome_url_overrides.newtab medium Replaces every new tab; high-reach surface, primary monetization vector for this category.

Pillar Scores

Permissions3.00
Reputation7.00
Network3.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00

Operator Siblings (1)

Other extensions sharing this developer's compound fingerprint:

Scoring History

sssiedn356e7915dp727562726963xsx 4.41 Medium block 2026-09-02
v3.6 6.52 High review 2026-08-28

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:45
Listing SHA 6c997515a19f…
Force block — not fired
Score recovered no
Elapsed