Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CyberGhost Cookie Cleaner

pbkgifljdgkhlmlmgbalmcknbhbggmei
Risk Score
6.31
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category PrivacyTool
Installs 60,000
Rating 4.3
Last updated 2022-01-20 (53 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@cyberghost.ro
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Extension not updated in 53 months (>4 years) — abandoned, no security patches.
  • cookies + browsingData + *://*/* combo enables full cross-site cookie exfiltration.
  • Privacy policy fetch failed; cannot confirm data handling for this extension.
  • new Function() constructor found in two JS files — dynamic code execution risk.
  • No CSP defined (MV3 mitigates partially, but no explicit policy is a gap).

Evidence

  • extreme_staleness store Last updated January 2022, 53 months ago. Scores +10.0 on maintenance pillar.
  • high_permission_combo manifest cookies + browsingData + *://*/* — ×1.2 amplifier applied; base HIGH perms sum ~6.25 → 7.5.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false → privacy pillar +10.0.
  • function_constructor_x2 crx new Function() in main-es5.js and main-es2015.js → code quality +2.5.
  • developer_name_missing store developer_name is empty string; reputation base +1.0 for missing dev name.
  • featured_by_google store is_featured_by_google=true → reputation -2.0 (featured discount).
  • no_csp manifest content_security_policy is null; MV3 strict default applies — no network +2.0 added.
  • triple_stale_fingerprint store >24mo + MV3 (not MV2, so v2 cal fix (c) MV2 condition not met) — maintenance dominates.

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; medium risk in combination with other permissions.
  • cookies high Read/write all cookies across all domains — core exfil vector.
  • history medium Full browsing history access; privacy-sensitive.
  • browsingData high Can clear cookies, cache, history — powerful destructive capability.
  • contextMenus low UI element only; low standalone risk.
  • notifications low Can display notifications; low risk without host pairing.
  • storage low Local extension storage; standard low risk.
  • *://*/* high Broad host access across all URLs; amplifies cookies+browsingData risk ×1.2.

Pillar Scores

Permissions7.50
Reputation5.00
Network2.00
Webstore1.00
Maintenance10.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA 3d9f09172962…
Force block — not fired
Score recovered no
Elapsed 24.7s