Is JavaScript-Java Bridge safe?
JavaScript-Java Bridge connects web pages on user-allowlisted sites to locally-installed native messaging hosts via a postMessage relay.
The extension replaces the deprecated Java browser plugin, enabling legacy Java applets that use LiveConnect to continue running without graphics. On pages matching the user-configured URL prefix allowlist, it injects a bridge script that reads the 'archive' attribute of <applet> DOM elements to determine which native messaging host to connect to, then relays messages between the page and that host through the background service worker. The native messaging host name comes directly from page content with no server-side validation, so any allowlisted page can open a long-lived port to any native messaging host installed on the system.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.81. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Store data in your browser
storage