Is Content Server Browser Web Extension safe?
Content Server Browser Web Extension exposes two unscoped bridges that allow any webpage to invoke OpenText native desktop applications.
The extension registers event listeners on all pages—a V3 CustomEvent handler and a legacy V2 DOM-event handler—that relay attacker-controlled parameters directly to native messaging hosts without origin validation. Any website can trigger these bridges to call methods on the OpenText desktop client, including passing arbitrary Application, Method, and Param fields to the native host. The legacy V2 path also reads cookies before forwarding the request to the native application.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itOpenText - 2 other listings from the same operator, none carrying a finding
OpenText - 2 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 10k+ users between them, none of them carrying a finding.
Same operator - 1 listing
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 3.0.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
*://*/
See the address and title of every tab you have open
tabs
Read and change cookies, including the ones that keep you signed in
cookies
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed OpenText Content Server contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.opentext.desktop.webext.messaging
OpenText Content Server sends data to com.opentext.desktop.webext.messaging. No other extension we have analysed sends data here.
- com.opentext.officeeditor.actionhandler
OpenText Content Server sends data to com.opentext.officeeditor.actionhandler. No other extension we have analysed sends data here.
- com.opentext.webdav.actionhandler
OpenText Content Server sends data to com.opentext.webdav.actionhandler. No other extension we have analysed sends data here.