Is Dolby Voice 1.2 safe?
Dolby Voice 1.2 injects a content script on all pages that relays any webpage's postMessage commands to a native host without adequate origin validation.
The extension's content script runs on every HTTP, HTTPS, and file URL and listens for postMessage events, checking only that the message originates from the same window rather than a trusted source. Any script running on a visited page can pass a controlled version string that gets concatenated directly into a native messaging host name and connected to via the extension background. Messages sent through this channel are forwarded verbatim to the native Dolby Voice launcher application, and responses are broadcast back to the page with no targetOrigin restriction.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging