Is Omnimed-QHR authenticator safe?
Omnimed-QHR authenticator forwards messages from Omnimed web pages to a local smartcard signing app without validating the request.
The extension lets Omnimed's healthcare web app talk to a locally installed native signing host (com.omnimed.native.signature) so Quebec healthcare workers can authenticate with their QHR access device. Any page from an allowed origin can send a message that the service worker passes straight to the native host, with no command allowlist or schema check beyond the externally_connectable origin list. That allowed list ships dev, test, stage and preprod origins plus two plaintext http:// origins in the production build, widening which pages can reach the signing channel.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.