Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Critical Role Fan Art: New Tab

ohlbophfiniejpeafcddbgkopgdcbkmp
Risk Score
6.38
Risk Level: High
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category NewTab
Installs 46
Rating 4.3
Last updated 2021-10-30 (56 months ago)
Manifest version MV2
CSP present ❌ no
Developer critternewtab@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: MV2 + bundled CVE + no-CSP + DOM-sink/eval finding = directly exploitable XSS surface on an unmaintained extension.
  • Abandoned: 56 months since last update with MV2 manifest and no CSP.
  • 4 moderate CVEs in bundled jquery@2.0.0 (XSS); no CSP amplifies DOM-XSS risk.
  • Privacy policy is generic Google account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • NewTab override with gmail-only dev identity and no business domain; shell-pattern flagged.

Evidence

  • months_since_update=56, MV2, no CSP manifest Extension last updated Oct 2021; over 36 months stale; MV2 with null CSP increases attack surface.
  • jquery@2.0.0 with 4 moderate CVEs crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 — all XSS; fixed_in up to 3.5.0.
  • dom_sink_innerhtml_userctrl + no CSP + CVEs crx innerHTML sink in jQuery with no CSP and active CVEs triggers FIX B elevated code-quality penalty.
  • generic Google privacy policy store Policy at myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • newtab override + gmail dev + is_shell_pattern manifest chrome_url_overrides.newtab set; dev email is gmail; description_promise.is_shell_pattern=true.
  • MV2 + no CSP network penalty manifest v2 calibration fix (b): +2.0 network for MV2 with no CSP. js_external_hosts has 8 entries across 3 countries.
  • free-webmail developer identity store Developer email critternewtab@gmail.com; no business website; no verified publisher badge.
  • triple-stale fingerprint store >24mo stale + CVEs present + MV2: v2 calibration fix (c) +2.0 webstore.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.0.0 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.0.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.0.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.0.0 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • chrome_url_overrides.newtab medium Replaces new-tab page; expected for NewTab category but carries hijack risk.

Pillar Scores

Permissions2.00
Reputation6.50
Network4.00
Webstore6.00
Maintenance10.00
Privacy10.00
Code Quality4.00
CVE Exposure4.50

Scoring History

v3.6 6.38 High block 2026-06-16
v3.4-rev 6.51 High block 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA 1cf485fe3d9c…
Force block 🚫 fired
Score recovered no
Elapsed 28.5s