Is Nuance PowerMic Web Extension safe?
Nuance PowerMic Web Extension injects a tracking cookie and device-control API into every HTTP/HTTPS page the user visits.
On each page load, the extension writes a one-year cookie to the visited site's origin cookie store, readable by any script on that page. It also injects a Nuance PowerMic adapter script into the page DOM, exposing microphone device-control APIs to page-level JavaScript without any origin restriction. For each tab, the extension opens a native messaging connection to the local Nuance host (com.nuance.pmicadapter), sending the tab ID and adapter URL—even on sites unrelated to Nuance.
Who publishes itNuance Communications, Inc. - 3 other listings from the same operator, none carrying a finding
Nuance Communications, Inc. - 3 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same operator - 3 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Extension Writes 365-Day Cookie to Every Visited Site
On every HTTP/HTTPS page, the content script writes a 365-day cookie NUSAI_CAVE_dontNotifyUser into that site's own store, no consent prompt, undisclosed in the listing.
Any script there, including ads, can read it and detect the extension.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-506
- Source
- Dynamic sandbox
You navigate to any website in your browser.
This applies to every HTTP and HTTPS page you visit; there is no allowlist or opt-out.
The extension writes a 365-day cookie to that site's cookie store without asking.
The cookie lands in the visited site's own origin, where any script on that page can read it.
- Cookie nameNUSAI_CAVE_dontNotifyUser
The name under which the cookie is stored in each visited site's cookie store.
- Cookie valuenotification_prevention
The static string written as the cookie value. It is identical on every site and for every user.
- Expiry365 days from the time of page load
How long the cookie persists in each site's cookie jar after it is set.
- Cookie originSet on example.com, healthcare-portal.net, and every other HTTP/HTTPS site you visit
Placed in each visited site's cookie store, not extension storage. Scripts on that site can read it to detect this extension.
Cookie injection code from content.js
// Inside init(), called unconditionally on every page at document_end.// No feature flag, consent check, or user preference is consulted.var notificationCookieName = "NUSAI_CAVE_dontNotifyUser"; // hard-coded namevar notificationCookieValue = "notification_prevention"; // hard-coded valuesetCookie(notificationCookieName, notificationCookieValue, 365); // 365-day lifetimefunction setCookie(c_name, value, exdays) { var exdate = new Date(); exdate.setDate(exdate.getDate() + exdays); // expiry = now + 365 days var c_value = encodeURIComponent(value) + "; expires=" + exdate.toUTCString() + "; path=/"; // no SameSite, no Secure, no HttpOnly // Writes to the VISITED PAGE'S cookie store, not the extension's own storage. // Any JavaScript running on this origin can read it back via document.cookie. document.cookie = c_name + "=" + c_value;}Checks whether the Nuance PowerMic extension cookie is present in the current page's cookie store. Paste this into the browser console on any site you have visited to confirm the cookie is there.
- Any modern browser console (Chrome, Firefox, Edge), no Node.js required
(function detectNuanceCookie() { var name = 'NUSAI_CAVE_dontNotifyUser'; var pairs = document.cookie.split(';').map(function(c) { return c.trim(); }); var match = pairs.find(function(c) { return c.startsWith(name + '='); }); if (match) { var value = decodeURIComponent(match.slice(name.length + 1)); console.log('[FOUND] Nuance PowerMic cookie is present on this origin:'); console.log(' Name : ' + name); console.log(' Value : ' + value); console.log(' Note : Any script running on this page can read the same value.'); } else { console.log('[NOT FOUND] Cookie ' + name + ' is not present on ' + location.hostname + '.'); console.log(' If the extension is installed, try navigating away and back — it fires on document_end.'); }})();- 1Open the browser console (F12 → Console) on any site you have visited with the Nuance PowerMic extension active, paste the script, and press Enter.
What it can do
Permissions this extension asks for, as declared in version 26.1.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 26.3.27.0, which we have not unpacked yet.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
See the address and title of every tab you have open
tabs
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Store data in your browser
storage
Schedule its own background tasks
alarms
See every page you navigate to, as you navigate to it
webNavigation
Show you desktop notifications
notifications
Run its own code inside the pages you visit
scripting