Infinity New Tab (Pro)
nnnkddnnlpamobajfibfdgfnbcnkgngh
Risk Score
6.52
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: arbitrary code execution); not patched to fixed_in 1.12.1.
- NewTab override contacts 4 distinct search engines (baidu, bing, google, yahoo) — multi-search-engine aggregator pattern (+2.5).
- Privacy policy fetched but scope_extension==false while admitting data collection and third-party sharing — scores 10.0.
- Free-webmail developer (gmail), no developer name listed — unverifiable identity raises accountability risk.
- function_constructor new Function() used across 10+ files including Vue template compiler and debugger tracing paths.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Currently bundled at vulnerable version.
- newtab_multi_search_engine crx search_engine_count=4 (baidu, bing, google, yahoo); NewTab+4 search engines triggers v3.5(C) +2.5.
- privacy_policy_scope_missing_data_collected api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.0.
- free_webmail_no_dev_name store Developer email infinitynewtab@gmail.com; developer_name empty. No verified publisher badge.
- function_constructor_widespread crx new Function() found in 10+ files including template compiler and debugger-injection strings.
- dom_xss_sink crx innerHTML assigned from variable in 4 files; csp_present=true but CVEs present → FIX B applies (+2.0).
- newtab_override manifest chrome_url_overrides.newtab replaces every new tab for 300K users; high-reach capability.
- js_external_hosts_cn_baidu crx 12 external JS hosts including baidu.com subdomains (CN-geolocated); country_count=2 (CN, US).
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab low Only accesses the active tab on user gesture; low ambient risk.
- storage low Local data persistence for settings; standard for NewTab extensions.
- unlimitedStorage low Allows larger local storage quota; no direct data-exfil vector.
- offscreen low Creates offscreen documents; MV3 pattern, limited scope here.
- background low Service worker background; declared redundantly in MV3 context.
- search medium Can query and potentially redirect browser search; sensitive for NewTab.
- chrome_url_overrides.newtab medium Replaces every new tab; high-reach surface, primary monetization vector for this category.
Pillar Scores
Permissions3.00
Reputation7.00
Network3.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00
Operator Siblings (1)
Other extensions sharing this developer's compound fingerprint:
Scoring History
| sssiedn356e7915dp727562726963xsx | 4.41 | Medium | block | 2026-09-02 |
| v3.6 | 6.52 | High | review | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 16:45
Listing SHA
6c997515a19f…
Force block
— not fired
Score recovered
no
Elapsed
—