Is Dolby Voice 1.1 safe?

Low risk

Dolby Voice 1.1 relays web page postMessages to a native messaging host with no origin or payload sanitization.

The extension injects a content script into all http, https, and file pages that listens for postMessages from the page. Any script running in the page can send a message that is forwarded verbatim to the native host com.dolby.voice.launcher, with the version string from the message used to construct the native host name. No cross-origin checks or payload filtering are applied before the data reaches the native application.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Dolby Laboratoriesv1.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 21 September 2026abpbcfijgmlbecbplnfknakoemncanbo