Is IBM Connections Cloud Meetings safe?

Low risk

IBM Connections Cloud Meetings bridges IBM Sametime meeting pages to a local native messaging host using a payload-field origin gate instead of event.origin.

The extension injects a script into IBM Sametime meeting room and web-player pages and relays window.postMessage messages to a background service that connects to the native host com.ibm.webplayer. The postMessage listener checks a hardcoded string in the message payload ('WPCE') rather than the standard event.origin field, meaning any script running in the same meeting page can trigger native messaging calls. No user data is transmitted to remote servers; all communication stays between the browser and the local IBM WebPlayer application.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

ibmsametimemeetingsv0.0.0.25Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 0.0.0.25. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    *://*/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See the address and title of every tab you have open

    tabs

  • Read and change cookies, including the ones that keep you signed in

    cookies

Updated 21 September 2026bdcoafpdlfhmdpnnicondenaabcfaokh