Is Omnimed-QHR authenticator safe?

Low risk

Omnimed-QHR authenticator forwards messages from Omnimed web pages to a local smartcard signing app without validating the request.

The extension lets Omnimed's healthcare web app talk to a locally installed native signing host (com.omnimed.native.signature) so Quebec healthcare workers can authenticate with their QHR access device. Any page from an allowed origin can send a message that the service worker passes straight to the native host, with no command allowlist or schema check beyond the externally_connectable origin list. That allowed list ships dev, test, stage and preprod origins plus two plaintext http:// origins in the production build, widening which pages can reach the signing channel.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

developpementOmnimedv3.0.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

com.omnimed.native.signature (local native host)omnimed.com web origins
Updated 17 September 2026beaeaepcpfakieomjhcnmiondgphipeg