Bookmarks clean up
oncbjlgldmiagjophlhobkogeladjijl
Risk Score
5.19
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; not patched to fixed_in 1.12.1.
- Privacy policy is Google's generic policy (scope_extension=false, admits data_collection+third_party_sharing): +10.0 privacy pillar.
- Developer uses free Gmail with no business domain; unverified identity raises account-takeover risk.
- Extension is 22 months stale with known critical/high CVEs in bundled library.
- Uninstall URL hijack detected; new Function() constructor in two JS files.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (Arbitrary Code Execution, critical, fixed in 1.12.1).
- high_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2026-27601 (DoS via unlimited recursion, high, fixed in 1.13.8).
- generic_privacy_policy store Privacy policy URL is Google's generic account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email bookmarkscleanupext@gmail.com; no business domain; unverified identity.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() to third-party target detected.
- function_constructor_usage crx new Function() constructor used in main.js and options.js (2 files); pattern consistent with bundled polyfill but elevates risk.
- stale_extension_with_cves store Last updated August 2024 (22 months); critical CVE in bundled lib unfixed.
- featured_by_google store Extension carries Google Featured badge, providing moderate reputation credit.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab low Grants access only to the currently active tab on user gesture; minimal risk.
- storage low Reads/writes extension-local storage; no sensitive cross-origin data.
- bookmarks medium Full read/write access to all bookmarks; matches stated function but broad.
Pillar Scores
Permissions1.60
Reputation6.50
Network0.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA
49d0e5118755…
Force block
— not fired
Score recovered
no
Elapsed
27.2s