Is Desktop companion app for Dynamics 365 Contact Center safe?
The extension relays postMessage payloads from any HTTPS page to the com.dynamics.vca native app without validating the sender's origin.
The content script listens for window.postMessage events on all HTTPS pages and forwards any message with direction set to MESSAGE_TO_VCA directly to the extension's service worker, which passes it to a native host application via chrome.runtime.connectNative. Because the handler checks only the message direction field and not event.origin, any web page running over HTTPS can send commands to the native Dynamics 365 Contact Center desktop companion without restriction.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itMicrosoft Corporation - 3 other listings from the same operator, none carrying a finding
Microsoft Corporation - 3 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same operator - 3 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Where it sends data
Destinations our analysis observed Desktop companion app for Dynamics 365 Contact Center contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.dynamics.vca
Desktop companion app for Dynamics 365 Contact Center sends data to com.dynamics.vca. No other extension we have analysed sends data here.