Is DICOM viewer extension safe?
DICOM viewer extension relays unvalidated page events to browser APIs, letting any website trigger native host calls and tab control.
The extension's content script runs on all HTTP and HTTPS pages and forwards CustomEvents fired by any web page directly to the background without origin validation. Through this relay, a page can send commands that connect to a native messaging host (dicom.printer.native.messaging), enumerate and manipulate open browser tabs (close, reload, resize, fullscreen), or read system memory information. The lack of origin checks means any website the user visits can invoke these privileged operations.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itBigroot Software a.s. - no other listings under this identity
Bigroot Software a.s. - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
See the address and title of every tab you have open
tabs
Act on the current tab, but only after you click the extension
activeTab
Run its own code inside the pages you visit
scripting
Read how much memory your computer has
system.memory
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging