Is MeetMe Dolby Voice 1.1 safe?
MeetMe Dolby Voice 1.1 relays postMessages from any web page to a native messaging host with no origin validation.
The extension injects a content script on all URLs and listens for window.postMessage events, checking only that the message originates from the same window rather than a trusted origin. When a connect command arrives, the content script forwards it to the background, which opens a native messaging channel to the com.meetme.dolby.voice.launcher host app installed on the user's machine. Unrecognized commands are passed directly to the native host, meaning any script running on any page can send arbitrary payloads to the native application.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.