Is IBM Aspera Connect safe?

Low risk

IBM Aspera Connect relays unvalidated messages from any web page to the locally-installed Aspera native host.

The extension injects a content script on all URLs that listens for CustomEvents and forwards their contents to a native messaging host (com.aspera.connect.nativemessagehost) without checking whether the originating page is an IBM or Aspera-approved domain. Any site can trigger this relay by dispatching an AsperaConnectRequest event. The extension also responds to AsperaConnectCheck events on any page by sending back the extension version number to all origins.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

IBM Asperav4.1.1.1Firefox Add-ons
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026amo-1015280