Zoom Video - UltraWide Video
ochhcgamjcnhpaekcckimgofnedofplf
Risk Score
4.88
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: mentions 'zoom' with gmail.com dev and no verified ownership, impersonating a major brand.
- Content script on <all_urls> injects code into every page visited, maximizing reach for any vulnerability.
- Two innerHTML DOM-XSS sinks in injected content scripts expose users to cross-site scripting on any page.
- Developer identity: no name, free webmail (gmail), no verified business — low accountability.
- Privacy policy lacks retention disclosure and third-party sharing is silent, limiting user visibility.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'zoom'; developer is xuanlamiesninh@gmail.com, confirmed_owner=false.
- host_permissions_all_urls manifest host_permissions=['<all_urls>'] plus content_scripts on '<all_urls>' — runs on every site.
- dom_xss_sinks crx 2x dom_sink_innerhtml_userctrl in contentScript.js and popup.js; csp_present but no script content from remote.
- free_webmail_no_dev_name store developer_name='', developer_email='xuanlamiesninh@gmail.com'; no business identity verifiable.
- privacy_policy_gaps api Policy fetched; scope_extension=true, data_collection=true, retention=false, third_party_silence=true.
- verified_publisher store verified_publisher=true; applies -1.0 cap discount (v3.5 invariant 0c not triggered — no stale/CVE/affiliate).
- large_install_base store 400,000 installs amplifies blast radius of any exploit or supply-chain compromise.
- external_host_reactjs_org crx js_external_hosts=['reactjs.org']; CSP is self-only so no remote script loading confirmed.
Permissions Breakdown
- storage low Stores extension settings locally; minimal risk.
- activeTab low Scoped access to current tab on user action; limited surface.
- <all_urls> (host_permission) high Content script injected on all URLs; broad reach across every site user visits.
Pillar Scores
Permissions6.00
Reputation7.50
Network2.00
Webstore4.50
Maintenance1.50
Privacy2.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
1d46aa5cc347…
Force block
— not fired
Score recovered
no
Elapsed
24.2s