Starmarks Bookmark Manager
ohhpijmpbgndokpodomgiclmflhbkihb
Risk Score
6.39
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); no CSP amplifies risk.
- Privacy policy is Google's generic account policy — does not scope to this extension; admits data collection and 3rd-party sharing.
- New-tab override combined with <all_urls> host permission creates broad surveillance surface from free-webmail dev.
- Developer uses gmail.com with no verified identity or business domain; free-webmail + no verified publisher.
- No CSP on MV3 extension with external JS hosts (tinyurl.com, underscorejs.org) and vulnerable bundled library.
Evidence
- critical_cve crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical); fixed in 1.12.1. No CSP present — v2 amplifier applies.
- high_cve crx underscore@1.8.3 has CVE-2026-27601 (DoS via recursion, high); fixed in 1.13.8.
- newtab_override manifest chrome_url_overrides.newtab set to src/extension/newtab/newtab.html — replaces every new tab.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- free_webmail_dev store Developer email casey1@gmail.com; no business domain, no verified publisher badge.
- external_hosts_no_csp crx 5 external JS hosts including tinyurl.com with no CSP; MV3 but no content_security_policy declared.
- host_permissions_all_urls manifest <all_urls> host permission paired with history and tabs broadens data-access surface.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 3000 installs with HIGH-tier host permissions.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- bookmarks medium Read/write all bookmarks; core function but sensitive browsing data.
- storage low Local extension data storage only.
- sidePanel low UI surface only, no data access.
- tabs medium Can read tab URLs and titles across all tabs.
- activeTab low Scoped to user-activated tab only.
- history medium Can read full browsing history; broad data access.
- <all_urls> (host_permissions) high Broad host access paired with tabs/history elevates risk significantly.
- chrome_url_overrides.newtab medium Replaces new-tab page; high visibility surface, potential monetization vector.
Pillar Scores
Permissions6.50
Reputation7.50
Network5.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
89388af8b809…
Force block
— not fired
Score recovered
no
Elapsed
43.0s