Is Dragon Medical Web Extension safe?

Low risk

Dragon Medical Web Extension accepts postMessage without origin checks on all pages, allowing any site to inject text into active editors.

The extension installs a content script on all URLs that listens for window postMessage events without validating the sender's origin. Any web page can send a specially crafted message using the extension's publicly known ID to invoke editor functions, including replacing text, reading typed content, or programmatically clicking page elements. Because the content script runs in all frames on every site, the attack surface covers every page the user visits.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Nuance Communications, Inc.v1.52.0.2934Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.52.0.2934. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 21 September 2026dkidoflkcabkfmcpnndogifoldoegnmk