Is NUSO Connect AC SIP safe?

Low risk

NUSO Connect AC SIP relays arbitrary page messages to a local native host via a forgeable sender-string gate.

The extension injects a content script on all HTTPS pages that listens for postMessage events. Any page script that sets the sender field to the string 'midasip_page' can cause the extension to open a connection to the native application 'com.midasolutions.midasip.chromium.nativehost' and forward messages to it verbatim. Responses from the native host are sent back to the originating page, with no origin allowlist beyond the forgeable constant.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Mida Solutionsv2.0.1Chrome Web Store
20Risk
Who publishes it

Mida Solutions - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Mida Solutions
Registered address
Via F. L. Wright, 7, Ravenna, RA 48124, IT
Registered contact
Marco Cortese

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed NUSO Connect AC SIP contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • com.midasolutions.midasip.chromium.nativehost (local native host)

    NUSO Connect AC SIP sends data to com.midasolutions.midasip.chromium.nativehost (local native host). Named as a recipient in this extension's own analysis.

Updated 30 September 2026ndjhacdnmppjahceomhghogpjmhpgoeg