Is IBM Aspera Connect safe?
IBM Aspera Connect relays unauthenticated CustomEvents from any website to the locally installed Aspera desktop app via native messaging.
The extension injects a content script on every page that listens for AsperaConnectRequest CustomEvents and forwards the full payload to the native host com.aspera.connect.nativemessagehost without checking the originating site. Any webpage can dispatch these events and drive the Aspera Connect desktop application's IPC channel. No authentication or origin validation is applied at the content script or background service worker layer.
Who publishes itInternational Business Machines Corporation - no other listings under this identity
International Business Machines Corporation - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 5.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Act on the current tab, but only after you click the extension
activeTab
Store data in your browser
storage
Run its own code inside the pages you visit
scripting
Where it sends data
Destinations our analysis observed IBM Aspera Connect contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.aspera.connect.nativemessagehost
IBM Aspera Connect sends data to com.aspera.connect.nativemessagehost. No other extension we have analysed sends data here.