Is Content Server Browser Web Extension safe?

Medium risk

Content Server Browser Web Extension exposes two unscoped bridges that allow any webpage to invoke OpenText native desktop applications.

The extension registers event listeners on all pages—a V3 CustomEvent handler and a legacy V2 DOM-event handler—that relay attacker-controlled parameters directly to native messaging hosts without origin validation. Any website can trigger these bridges to call methods on the OpenText desktop client, including passing arbitrary Application, Method, and Param fields to the native host. The legacy V2 path also reads cookies before forwarding the request to the native application.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

OpenText Corporationv3.0.0.0Chrome Web Store
45Risk
Who publishes it

OpenText - 2 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
OpenText Corporation
Declared legal entity
OpenText
Registered address
275 Frank Tompa Dr, Waterloo, ON N2L 0A1, CA
Registered contact
OpenText Corporation

Same store account

1 other listing published from this account, 10k+ users between them, none of them carrying a finding.

Same operator - 1 listing

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.0.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/

  • See the address and title of every tab you have open

    tabs

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed OpenText Content Server contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • com.opentext.desktop.webext.messaging

    OpenText Content Server sends data to com.opentext.desktop.webext.messaging. No other extension we have analysed sends data here.

  • com.opentext.officeeditor.actionhandler

    OpenText Content Server sends data to com.opentext.officeeditor.actionhandler. No other extension we have analysed sends data here.

  • com.opentext.webdav.actionhandler

    OpenText Content Server sends data to com.opentext.webdav.actionhandler. No other extension we have analysed sends data here.

Updated 30 September 2026hlphpjodcfdblfmbbdjodbfmlonmidfh