Is Dolby Voice 1.2 safe?

Low risk

Dolby Voice 1.2 injects a content script on all pages that relays any webpage's postMessage commands to a native host without adequate origin validation.

The extension's content script runs on every HTTP, HTTPS, and file URL and listens for postMessage events, checking only that the message originates from the same window rather than a trusted source. Any script running on a visited page can pass a controlled version string that gets concatenated directly into a native messaging host name and connected to via the extension background. Messages sent through this channel are forwarded verbatim to the native Dolby Voice launcher application, and responses are broadcast back to the page with no targetOrigin restriction.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Dolby Laboratoriesv1.2Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 21 September 2026kaimfhiiegblglllpkcpoegelgefonef