Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bookmarks clean up

oncbjlgldmiagjophlhobkogeladjijl
Risk Score
5.19
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 200,000
Rating 4.4
Last updated 2024-08-10 (22 months ago)
Manifest version MV3
CSP present ✅ yes
Developer bookmarkscleanupext@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; not patched to fixed_in 1.12.1.
  • Privacy policy is Google's generic policy (scope_extension=false, admits data_collection+third_party_sharing): +10.0 privacy pillar.
  • Developer uses free Gmail with no business domain; unverified identity raises account-takeover risk.
  • Extension is 22 months stale with known critical/high CVEs in bundled library.
  • Uninstall URL hijack detected; new Function() constructor in two JS files.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (Arbitrary Code Execution, critical, fixed in 1.12.1).
  • high_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2026-27601 (DoS via unlimited recursion, high, fixed in 1.13.8).
  • generic_privacy_policy store Privacy policy URL is Google's generic account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email bookmarkscleanupext@gmail.com; no business domain; unverified identity.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() to third-party target detected.
  • function_constructor_usage crx new Function() constructor used in main.js and options.js (2 files); pattern consistent with bundled polyfill but elevates risk.
  • stale_extension_with_cves store Last updated August 2024 (22 months); critical CVE in bundled lib unfixed.
  • featured_by_google store Extension carries Google Featured badge, providing moderate reputation credit.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • activeTab low Grants access only to the currently active tab on user gesture; minimal risk.
  • storage low Reads/writes extension-local storage; no sensitive cross-origin data.
  • bookmarks medium Full read/write access to all bookmarks; matches stated function but broad.

Pillar Scores

Permissions1.60
Reputation6.50
Network0.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA 49d0e5118755…
Force block — not fired
Score recovered no
Elapsed 27.2s