Is Belfius Smart Card Reader Chrome Extension safe?

Low risk

Belfius Smart Card Reader relays commands from permitted web pages to a native card reader host via native messaging.

The extension acts as a bridge between Belfius banking pages and a locally installed native host (com.belfius.cardreader.extension), forwarding messages from externally connectable origins to the card reader. It accepts connections from belfius.be pages over HTTPS and from a Vasco demo origin over plain HTTP (http://dp.demo.vasco.com/DP870_EXT/*). The plain-HTTP origin means a network-level attacker positioned between the browser and that server could connect to the extension and relay arbitrary commands to the native card reader host.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

iws-groupv2.3.2.2Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.3.2.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 21 September 2026agicnfmechmlphpjmeefookfjhifbmhi