Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cleaner - history & cache clean

pooaemmkohlphkekccfajnbcokjlbehk
Risk Score
6.61
Risk Level: High
Recommendation: 🚫 BLOCK
Category PrivacyTool
Installs 100,000
Rating 4.8
Last updated 2025-12-29 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer cleaner_help@hotmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + *://*/* host access enables reading/exfiltrating all browser cookies from any site
  • Uninstall AND install URL hijack both present — classic traffic-monetization/redirect pattern
  • Privacy policy is generic Google account policy — does not scope to this extension at all (D-rule: admits data collection + 3rd-party sharing)
  • Developer uses free Hotmail email with no verified publisher badge and generic 'Smart extension' name
  • jQuery 3.4.1 bundled with two medium XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP to mitigate

Evidence

  • cookies + *://*/* host permissions manifest cookies HIGH permission paired with broad host access *://*/* — ×1.2 multiplier applied; can exfiltrate all cookies.
  • uninstall_url_hijack + install_url_hijack both true crx Both onInstall and uninstall URL hijacks active — webstore +3.0 (uninstall) +2.0 (install) traffic-monetization signals.
  • Privacy policy is generic Google account policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D-rule).
  • Free webmail developer email store cleaner_help@hotmail.com — free webmail, no verified publisher, no business domain; reputation floor applies.
  • jQuery 3.4.1 with CVE-2020-11022 and CVE-2020-11023 crx Two medium-severity XSS CVEs; fixed_in 3.5.0; no CSP present to mitigate DOM sinks.
  • External JS host smartcleaner.online crx Extension contacts smartcleaner.online — developer-controlled but not a recognized domain; adds network surface.
  • is_featured_by_google = true store Google Featured badge applies -2.0 reputation discount but does not override hotmail+no-verified-publisher risk floor.
  • No CSP present (csp_present=false) on MV3 manifest No content_security_policy declared; CVE XSS libs have no mitigation layer.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Stores extension settings; low standalone risk.
  • browsingData high Core function but grants ability to delete all browser history, cookies, cache.
  • tabs medium Can read tab URLs and titles; paired with broad host access raises risk.
  • cookies high Can read/write/delete cookies for any domain; HIGH risk especially with *://*/*.
  • alarms low Schedules background tasks; minimal standalone risk.
  • *://*/* high Broad host access paired with cookies = critical capability multiplier.

Pillar Scores

Permissions8.00
Reputation6.00
Network4.00
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:58
Listing SHA 026598d0a2da…
Force block — not fired
Score recovered no
Elapsed