Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Browsec VPN - Free VPN for Chrome

omghfjlpggmjjaagoclmmobgdodcjboh
Risk Score
4.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 8,000,000
Rating 4.5
Last updated 2026-07-09 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@browsec.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 — arbitrary code execution; unfixed (need >=1.12.1).
  • CSP connect-src lists 80+ low-reputation HTTP CDN domains (cacheflow, fastfetch, datafrenzy, etc.) — anomalous for a VPN.
  • Privacy policy fetched but scope_extension==false and data_collection==true — policy does not specify what THIS extension collects.
  • proxy+webRequest+scripting+browsingData+<all_urls> is maximum traffic-interception capability; expected for VPN but very high blast radius.
  • uninstall_url_hijack == true — extension registers an uninstall redirect URL.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical) and CVE-2026-27601 (DoS, high); fixed_in 1.13.8.
  • csp_connect_src_excessive_domains crx connect-src whitelists 80+ opaque HTTP CDN domains (cacheflow.cloud, datafrenzy.org, fastfetch.xyz, etc.).
  • privacy_policy_not_scoped store Policy fetched; data_collection=true, scope_extension=false — does not disclose what this extension collects.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() called on uninstall; target URL not resolved.
  • function_constructor_multiple_files crx new Function() used in 6 page scripts; snippet suggests library polyfill pattern but still a code-quality risk.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; 8M installs, rating 4.5 — strong positive trust signals.
  • high_permissions_vp_category_discount manifest VPN category justifies proxy+webRequest+browsingData+<all_urls>; -1.5 justified-broad-permission discount applied.
  • js_external_hosts_9_domains crx 9 external JS hosts including gist.githubusercontent.com, gh-proxy.com, www.google-analytics.com.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • proxy high Full proxy control — can reroute all browser traffic through any server.
  • webRequest high Intercepts all HTTP requests; combined with proxy and <all_urls> is maximum-reach.
  • browsingData high Can delete history, cookies, cache across all sites.
  • scripting high Programmatic script injection into any page given <all_urls> host permission.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • webRequestAuthProvider medium Provides credentials for proxy auth challenges — sensitive credential surface.
  • storage low Local key-value store; low risk in isolation.
  • alarms low Scheduling only; minimal risk.
  • background low Persistent background service worker; expected for VPN.
  • <all_urls> high Broad host access amplifies proxy+scripting+webRequest to cover every site visited.

Pillar Scores

Permissions6.50
Reputation2.00
Network5.50
Webstore3.00
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure7.00

Scoring History

sssieddrubricxsx 5.14 Medium review 2026-08-10
v3.6 4.73 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA 328c8a28b089…
Force block — not fired
Score recovered no
Elapsed 34.3s