Is CFCA CertEnrollment.ChinaTRC_V3 Extension safe?
CFCA CertEnrollment relays messages from a narrow set of internal addresses to a local PKI app without validating the command.
The extension listens for external messages and forwards a caller-supplied native-messaging host name and payload straight through to a local native application, with no schema or command checks once the message arrives. Only around 40 origins can reach it, almost all private internal network addresses (10.x/11.x/172.x) plus one CFCA-owned wildcard domain, so exposure is limited to that specific corporate network rather than the open web.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.