Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cute Cat Wallpapers New Tab

paajmlioglbkjeealiikpiiddbbhcaan
Risk Score
6.12
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category NewTab
Installs 1,000
Rating 4.0
Last updated 2024-04-10 (28 months ago)
Manifest version MV3
CSP present ✅ yes
Developer funnyextensions@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab override contacts mystart.com/vmn.net ad-tech cluster and Yahoo Search — dual-search-engine monetization pattern.
  • jquery@2.2.4 bundles 4 moderate CVEs (XSS); version unfixed and bundled with no CSP script-src upgrade path.
  • Uninstall and install URL hijacks present; target not disclosed — classic monetization shell behavior.
  • 28-month-stale extension with free-webmail dev, no developer name, and gmail-only identity — high accountability gap.
  • function_constructor and eval_user_input in JS create code-execution risk compounded by vulnerable jQuery DOM sinks.

Evidence

  • newtab_override_with_ad_network crx chrome_url_overrides.newtab set; js_external_hosts include mystart.com, vmn.net, yahoo search — monetization cluster.
  • uninstall_and_install_url_hijack crx uninstall_url_hijack=true, install_url_hijack=true; targets null but hooks declared — monetization shell signal.
  • jquery_cve_cluster crx jquery@2.2.4 has 4 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed_in 3.5.0.
  • code_quality_eval_function_constructor crx new Function() in newtab/js/index.js and eval() in require.js; both eval user-controlled strings.
  • dom_xss_sinks crx innerHTML assignments in index.js and jquery.js; combined with CVEs raises DOM-XSS exploitation risk.
  • stale_freeemail_no_devname store 28mo since update; developer_name empty; email funnyextensions@gmail.com — no verified identity.
  • dual_search_engine_newtab crx search_engine_count=2 (google.com + yahoo.com) on NewTab extension — ad-monetization aggregator signal.
  • monetization_hits api threat_intel.monetization_hits: google-analytics telemetry; mystart/vmn ad network hosts in js_external_hosts.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.2.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.2.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Stores user preferences locally; standard for NewTab extensions.
  • topSites medium Reads user's most-visited sites; reasonable for NewTab but is personal data.
  • tabs medium Access to tab URLs/titles; broader than strictly needed for a wallpaper NewTab.
  • chrome_url_overrides.newtab medium Replaces every new tab; high reach, persistent user-facing surface area.

Pillar Scores

Permissions3.50
Reputation7.50
Network4.50
Webstore7.50
Maintenance8.50
Privacy1.00
Code Quality6.50
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:38
Listing SHA 873b3118282b…
Force block — not fired
Score recovered no
Elapsed