Is Polycom® RealPresence® Web Suite Extension safe?

Low risk

Polycom RealPresence Web Suite Extension exposes native host messaging and screen capture to any HTTPS page via postMessage bridges.

Two broad-scope content scripts (media-content.min.js and ecs-content.min.js) run on all HTTPS pages and listen for window.postMessage events. Both gates check that the incoming message's src field matches a string built from the fixed, public extension ID, which any page can construct. Through these bridges, any page can relay arbitrary commands to the Polycom native host application or trigger a desktop capture prompt and retrieve a screen frame.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Polycomv2.2.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every secure site you visit

    https://*/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See the address and title of every tab you have open

    tabs

  • Act on the current tab, but only after you click the extension

    activeTab

  • Keep running in the background while your browser is open

    background

  • Store an unlimited amount of data in your browser

    unlimitedStorage

  • Capture the contents of your screen, window or a tab

    desktopCapture

  • Route all of your browsing through a server of its choosing

    proxy

Updated 21 September 2026djidlmindihfdjgfedhgpfbpkjafcjcl