Is Nuance PowerMic Web Extension safe?

Medium risk

Nuance PowerMic Web Extension injects a tracking cookie and device-control API into every HTTP/HTTPS page the user visits.

On each page load, the extension writes a one-year cookie to the visited site's origin cookie store, readable by any script on that page. It also injects a Nuance PowerMic adapter script into the page DOM, exposing microphone device-control APIs to page-level JavaScript without any origin restriction. For each tab, the extension opens a native messaging connection to the local Nuance host (com.nuance.pmicadapter), sending the tab ID and adapter URL—even on sites unrelated to Nuance.

cavesdkdevelopmentv26.3.27.0Chrome Web Store
49Risk
Who publishes it

Nuance Communications, Inc. - 3 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
cavesdkdevelopment
Declared legal entity
Nuance Communications, Inc.
Registered address
1 Wayside Rd, Burlington, MA 01803-4609, US
Registered contact
Nuance Communications, Inc.

Same operator - 3 listings

Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Extension Writes 365-Day Cookie to Every Visited Site

On every HTTP/HTTPS page, the content script writes a 365-day cookie NUSAI_CAVE_dontNotifyUser into that site's own store, no consent prompt, undisclosed in the listing.

Any script there, including ads, can read it and detect the extension.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-506
Source
Dynamic sandbox
What actually happens
You did this

You navigate to any website in your browser.

This applies to every HTTP and HTTPS page you visit; there is no allowlist or opt-out.

The extension did this

The extension writes a 365-day cookie to that site's cookie store without asking.

The cookie lands in the visited site's own origin, where any script on that page can read it.

Cookie placed on every visited page
  • Cookie name
    NUSAI_CAVE_dontNotifyUser

    The name under which the cookie is stored in each visited site's cookie store.

  • Cookie value
    notification_prevention

    The static string written as the cookie value. It is identical on every site and for every user.

  • Expiry
    365 days from the time of page load

    How long the cookie persists in each site's cookie jar after it is set.

  • Cookie origin
    Set on example.com, healthcare-portal.net, and every other HTTP/HTTPS site you visit

    Placed in each visited site's cookie store, not extension storage. Scripts on that site can read it to detect this extension.

The code that does this

Cookie injection code from content.js

Readable version
// Inside init(), called unconditionally on every page at document_end.// No feature flag, consent check, or user preference is consulted.var notificationCookieName  = "NUSAI_CAVE_dontNotifyUser"; // hard-coded namevar notificationCookieValue = "notification_prevention";   // hard-coded valuesetCookie(notificationCookieName, notificationCookieValue, 365); // 365-day lifetimefunction setCookie(c_name, value, exdays) {    var exdate = new Date();    exdate.setDate(exdate.getDate() + exdays); // expiry = now + 365 days    var c_value = encodeURIComponent(value)        + "; expires=" + exdate.toUTCString()        + "; path=/";     // no SameSite, no Secure, no HttpOnly    // Writes to the VISITED PAGE'S cookie store, not the extension's own storage.    // Any JavaScript running on this origin can read it back via document.cookie.    document.cookie = c_name + "=" + c_value;}
Check if you're affected

Checks whether the Nuance PowerMic extension cookie is present in the current page's cookie store. Paste this into the browser console on any site you have visited to confirm the cookie is there.

Requires
  • Any modern browser console (Chrome, Firefox, Edge), no Node.js required
detect-nuance-cookie.js · js
(function detectNuanceCookie() {  var name = 'NUSAI_CAVE_dontNotifyUser';  var pairs = document.cookie.split(';').map(function(c) { return c.trim(); });  var match = pairs.find(function(c) { return c.startsWith(name + '='); });  if (match) {    var value = decodeURIComponent(match.slice(name.length + 1));    console.log('[FOUND] Nuance PowerMic cookie is present on this origin:');    console.log('  Name  : ' + name);    console.log('  Value : ' + value);    console.log('  Note  : Any script running on this page can read the same value.');  } else {    console.log('[NOT FOUND] Cookie ' + name + ' is not present on ' + location.hostname + '.');    console.log('  If the extension is installed, try navigating away and back — it fires on document_end.');  }})();
How to run it
  1. 1Open the browser console (F12 → Console) on any site you have visited with the Nuance PowerMic extension active, paste the script, and press Enter.

What it can do

Permissions this extension asks for, as declared in version 26.1.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 26.3.27.0, which we have not unpacked yet.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • See the address and title of every tab you have open

    tabs

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Store data in your browser

    storage

  • Schedule its own background tasks

    alarms

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Show you desktop notifications

    notifications

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026fmiojochalhealflohaicjncoofdjjfb