Cute Cat Wallpapers New Tab
paajmlioglbkjeealiikpiiddbbhcaan
Risk Score
6.12
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- NewTab override contacts mystart.com/vmn.net ad-tech cluster and Yahoo Search — dual-search-engine monetization pattern.
- jquery@2.2.4 bundles 4 moderate CVEs (XSS); version unfixed and bundled with no CSP script-src upgrade path.
- Uninstall and install URL hijacks present; target not disclosed — classic monetization shell behavior.
- 28-month-stale extension with free-webmail dev, no developer name, and gmail-only identity — high accountability gap.
- function_constructor and eval_user_input in JS create code-execution risk compounded by vulnerable jQuery DOM sinks.
Evidence
- newtab_override_with_ad_network crx chrome_url_overrides.newtab set; js_external_hosts include mystart.com, vmn.net, yahoo search — monetization cluster.
- uninstall_and_install_url_hijack crx uninstall_url_hijack=true, install_url_hijack=true; targets null but hooks declared — monetization shell signal.
- jquery_cve_cluster crx jquery@2.2.4 has 4 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed_in 3.5.0.
- code_quality_eval_function_constructor crx new Function() in newtab/js/index.js and eval() in require.js; both eval user-controlled strings.
- dom_xss_sinks crx innerHTML assignments in index.js and jquery.js; combined with CVEs raises DOM-XSS exploitation risk.
- stale_freeemail_no_devname store 28mo since update; developer_name empty; email funnyextensions@gmail.com — no verified identity.
- dual_search_engine_newtab crx search_engine_count=2 (google.com + yahoo.com) on NewTab extension — ad-monetization aggregator signal.
- monetization_hits api threat_intel.monetization_hits: google-analytics telemetry; mystart/vmn ad network hosts in js_external_hosts.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.2.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.2.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Stores user preferences locally; standard for NewTab extensions.
- topSites medium Reads user's most-visited sites; reasonable for NewTab but is personal data.
- tabs medium Access to tab URLs/titles; broader than strictly needed for a wallpaper NewTab.
- chrome_url_overrides.newtab medium Replaces every new tab; high reach, persistent user-facing surface area.
Pillar Scores
Permissions3.50
Reputation7.50
Network4.50
Webstore7.50
Maintenance8.50
Privacy1.00
Code Quality6.50
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:38
Listing SHA
873b3118282b…
Force block
— not fired
Score recovered
no
Elapsed
—