Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Toggl Track: Productivity & Time Tracker

oejgccbfbmkkpaidnkphaiaecficdnfn
Risk Score
4.05
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 400,000
Rating 4.4
Last updated 2026-06-10
Manifest version MV3
CSP present ✅ yes
Developer support@toggl.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (Arbitrary Code Execution); not patched.
  • High CVE-2026-27601 in underscore@1.8.3 (DoS via recursion); not patched.
  • Privacy policy fetched but scope_extension==false and admits 3rd-party data sharing without extension-specific scope → +10.0 privacy pillar.
  • No developer name listed in store; email domain toggl.com resolves but publisher not verified.
  • Uninstall URL hijack flag set true; though target null, signal warrants review.

Evidence

  • cve_critical crx underscore@1.8.3 bundles CVE-2021-23358 (Arbitrary Code Execution); fixed in 1.12.1.
  • cve_high crx underscore@1.8.3 bundles CVE-2026-27601 (DoS recursion); fixed in 1.13.8.
  • privacy_scope_missing store Policy at toggl.com/legal/track/privacy/ does not scope to this extension; admits 3rd-party sharing.
  • uninstall_url_hijack crx uninstall_url_hijack==true; target URL null so hijack destination unknown.
  • cookies_permission manifest cookies permission declared; host-scoped to toggl.com only, limiting blast radius.
  • featured_by_google store Extension marked is_featured_by_google=true; positive trust signal.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; no active malicious behaviour detected.
  • external_hosts crx 12 external JS hosts including momentjs.com, radix-ui.com, robwu.nl outside toggl.com cluster.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • alarms low Schedules timer reminders; expected for time tracker.
  • background low Keeps timer running in background; expected.
  • contextMenus low Adds right-click timer controls; low risk.
  • idle low Detects idle to pause timer; expected function.
  • notifications low Timer alerts; expected for productivity tool.
  • scripting medium Can inject scripts into pages; scoped to toggl.com host perms.
  • storage low Local config/state; standard.
  • cookies high Can read cookies; host-scoped to toggl.com only, reduces blast radius.
  • offscreen low Offscreen document for audio/DOM; low risk.
  • unlimitedStorage low Extended local storage for time entries; expected.

Pillar Scores

Permissions3.50
Reputation4.00
Network2.50
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure7.00

Scoring History

v3.6 4.05 Medium review 2026-06-16
v3.4-rev 3.12 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA 23b1ac1aacbc…
Force block — not fired
Score recovered no
Elapsed 25.4s