Is Horizon HTML5 Redirection Extension safe?
The extension exposes an unauthenticated WebSocket proxy to every webpage via a content script injected into all URLs.
Horizon HTML5 Redirection Extension bridges the browser to a locally-running VMware Horizon client using native messaging (com.vmware.html5mmr / com.horizon.html5mmr). The background script connects to a local WebSocket server (wss://view-localhost:<port>) and relays the port number to content scripts. The content script, running in every page and frame, accepts postMessage commands using only a hard-coded group key to open, send data through, and close arbitrary WebSocket connections — any page script that knows the static key can use this proxy.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itOmnissa HoldCo LLC - 5 other listings from the same operator, none carrying a finding
Omnissa HoldCo LLC - 5 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
5 other listings published from this account, 703k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 8.14.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 8.19.0.0, which we have not unpacked yet.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Run its own code inside the pages you visit
scripting
Watch every request your browser makes
webRequest