Cyberhaven security extension
pajkjnmeojmbapicmbpliphjmcekeaac
Risk Score
6.29
Risk Level:
High
Recommendation:
🚫 BLOCK
FORCE-BLOCK
Top Risks
- FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
- Extreme permission surface: cookies+scripting+webRequest+management+<all_urls> can read all data, inject code, intercept any request, and control other extensions.
- Privacy policy not scoped to this extension despite confirmed data collection and third-party sharing — policy admits broad data flows without extension-specific disclosure.
- Uninstall URL hijack set; extension registers a third-party destination on uninstall (target not disclosed).
- Low rating (1.8) at 100K installs without verified publisher badge raises accountability concerns.
Evidence
- high_permission_combo manifest cookies+scripting+webRequest+management+<all_urls>: can exfiltrate session tokens and inject code on any site.
- uninstall_url_hijack crx uninstall_url_hijack=true with null target; extension registers uninstall callback to undisclosed URL.
- privacy_policy_not_scoped api scope_extension=false, data_collection=true, third_party_sharing=true — policy admits sharing without extension scope.
- low_rating store Rating 1.8 at 100K installs; no rating_count supplied; no verified publisher badge.
- broad_content_scripts manifest 120+ content_script matches including AWS console, GitHub, Google Workspace, Slack, Outlook.
- csp_localhost_ports manifest CSP connect-src includes 10 localhost ports (10584-46585); suggests companion app or dev artifacts.
- no_cve_findings crx cve_findings_raw empty; no known-vulnerable bundled libraries detected.
- no_code_quality_findings crx code_findings_raw empty, obfuscation_score=0.0; 239 JS files scanned with no AST-level findings.
Permissions Breakdown
- alarms low Schedules background tasks; low standalone risk.
- tabs medium Reads tab URLs and titles across all sites.
- downloads medium Can monitor and intercept file downloads.
- webNavigation medium Tracks navigation events across all pages.
- webRequest high Intercepts all HTTP requests; broad surveillance capability.
- declarativeNetRequestWithHostAccess high Can block/redirect network requests across all hosts.
- storage low Local extension data storage; low risk alone.
- cookies high Read/write cookies on all domains; paired with <all_urls> — critical.
- scripting high Injects scripts into any page; combined with <all_urls> is highest risk.
- management high Can enumerate/disable/enable other extensions.
- identity medium Access to Chrome identity APIs for OAuth tokens.
- identity.email medium Reads user's Google account email address.
- offscreen low Creates offscreen documents; limited risk without other indicators.
- idle low Detects user idle state; minimal risk.
- <all_urls> high Broad host access amplifying every other high-risk permission.
Pillar Scores
Permissions9.50
Reputation5.50
Network3.50
Webstore4.00
Maintenance0.00
Privacy4.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 17:01
Listing SHA
93a3e4843de4…
Force block
🚫 fired
Score recovered
no
Elapsed
—