Critical Role Fan Art: New Tab
ohlbophfiniejpeafcddbgkopgdcbkmp
Risk Score
6.38
Risk Level:
High
Recommendation:
🚫 BLOCK
FORCE-BLOCK
Top Risks
- FORCE BLOCK: MV2 + bundled CVE + no-CSP + DOM-sink/eval finding = directly exploitable XSS surface on an unmaintained extension.
- Abandoned: 56 months since last update with MV2 manifest and no CSP.
- 4 moderate CVEs in bundled jquery@2.0.0 (XSS); no CSP amplifies DOM-XSS risk.
- Privacy policy is generic Google account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- NewTab override with gmail-only dev identity and no business domain; shell-pattern flagged.
Evidence
- months_since_update=56, MV2, no CSP manifest Extension last updated Oct 2021; over 36 months stale; MV2 with null CSP increases attack surface.
- jquery@2.0.0 with 4 moderate CVEs crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 — all XSS; fixed_in up to 3.5.0.
- dom_sink_innerhtml_userctrl + no CSP + CVEs crx innerHTML sink in jQuery with no CSP and active CVEs triggers FIX B elevated code-quality penalty.
- generic Google privacy policy store Policy at myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- newtab override + gmail dev + is_shell_pattern manifest chrome_url_overrides.newtab set; dev email is gmail; description_promise.is_shell_pattern=true.
- MV2 + no CSP network penalty manifest v2 calibration fix (b): +2.0 network for MV2 with no CSP. js_external_hosts has 8 entries across 3 countries.
- free-webmail developer identity store Developer email critternewtab@gmail.com; no business website; no verified publisher badge.
- triple-stale fingerprint store >24mo stale + CVEs present + MV2: v2 calibration fix (c) +2.0 webstore.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.0.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.0.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.0.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.0.0 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- chrome_url_overrides.newtab medium Replaces new-tab page; expected for NewTab category but carries hijack risk.
Pillar Scores
Permissions2.00
Reputation6.50
Network4.00
Webstore6.00
Maintenance10.00
Privacy10.00
Code Quality4.00
CVE Exposure4.50
Scoring History
| v3.6 | 6.38 | High | block | 2026-06-16 |
| v3.4-rev | 6.51 | High | block | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
1cf485fe3d9c…
Force block
🚫 fired
Score recovered
no
Elapsed
28.5s