Is Topaz SigIDExtLite Extension safe?
Topaz SigIDExtLite relays page-supplied commands to a local fingerprint driver on any website without origin validation.
The extension injects a content script on every website that listens for a DOM CustomEvent and forwards the caller-supplied JSON payload to the native host com.topaz.sigidextlite.win via native messaging. Because no validation of the initiating page's origin is performed, any site can dispatch the event and send arbitrary commands to the locally installed Topaz fingerprint driver. Responses from the native host are passed back to the originating page through the same DOM event channel.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itTopaz Systems, Inc. - 2 other listings from the same operator, 2 of them carrying a finding
Topaz Systems, Inc. - 2 other listings from the same operator, 2 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
2 other listings published from this account, 1.2M+ users between them. 2 of them carry a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.2.3.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed Topaz SigIDExtLite Extension contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.topaz.sigidextlite.win
Topaz SigIDExtLite Extension sends data to com.topaz.sigidextlite.win. No other extension we have analysed sends data here.