Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cyberhaven security extension

pajkjnmeojmbapicmbpliphjmcekeaac
Risk Score
6.29
Risk Level: High
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category Security
Installs 100,000
Rating 1.8
Last updated 2026-08-12
Manifest version MV3
CSP present ✅ yes
Developer support@cyberhaven.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • Extreme permission surface: cookies+scripting+webRequest+management+<all_urls> can read all data, inject code, intercept any request, and control other extensions.
  • Privacy policy not scoped to this extension despite confirmed data collection and third-party sharing — policy admits broad data flows without extension-specific disclosure.
  • Uninstall URL hijack set; extension registers a third-party destination on uninstall (target not disclosed).
  • Low rating (1.8) at 100K installs without verified publisher badge raises accountability concerns.

Evidence

  • high_permission_combo manifest cookies+scripting+webRequest+management+<all_urls>: can exfiltrate session tokens and inject code on any site.
  • uninstall_url_hijack crx uninstall_url_hijack=true with null target; extension registers uninstall callback to undisclosed URL.
  • privacy_policy_not_scoped api scope_extension=false, data_collection=true, third_party_sharing=true — policy admits sharing without extension scope.
  • low_rating store Rating 1.8 at 100K installs; no rating_count supplied; no verified publisher badge.
  • broad_content_scripts manifest 120+ content_script matches including AWS console, GitHub, Google Workspace, Slack, Outlook.
  • csp_localhost_ports manifest CSP connect-src includes 10 localhost ports (10584-46585); suggests companion app or dev artifacts.
  • no_cve_findings crx cve_findings_raw empty; no known-vulnerable bundled libraries detected.
  • no_code_quality_findings crx code_findings_raw empty, obfuscation_score=0.0; 239 JS files scanned with no AST-level findings.

Permissions Breakdown

  • alarms low Schedules background tasks; low standalone risk.
  • tabs medium Reads tab URLs and titles across all sites.
  • downloads medium Can monitor and intercept file downloads.
  • webNavigation medium Tracks navigation events across all pages.
  • webRequest high Intercepts all HTTP requests; broad surveillance capability.
  • declarativeNetRequestWithHostAccess high Can block/redirect network requests across all hosts.
  • storage low Local extension data storage; low risk alone.
  • cookies high Read/write cookies on all domains; paired with <all_urls> — critical.
  • scripting high Injects scripts into any page; combined with <all_urls> is highest risk.
  • management high Can enumerate/disable/enable other extensions.
  • identity medium Access to Chrome identity APIs for OAuth tokens.
  • identity.email medium Reads user's Google account email address.
  • offscreen low Creates offscreen documents; limited risk without other indicators.
  • idle low Detects user idle state; minimal risk.
  • <all_urls> high Broad host access amplifying every other high-risk permission.

Pillar Scores

Permissions9.50
Reputation5.50
Network3.50
Webstore4.00
Maintenance0.00
Privacy4.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 17:01
Listing SHA 93a3e4843de4…
Force block 🚫 fired
Score recovered no
Elapsed