Is CFCA CertEnrollment.ChinaTRC_V3 Extension safe?

Low risk

CFCA CertEnrollment relays messages from a narrow set of internal addresses to a local PKI app without validating the command.

The extension listens for external messages and forwards a caller-supplied native-messaging host name and payload straight through to a local native application, with no schema or command checks once the message arrives. Only around 40 origins can reach it, almost all private internal network addresses (10.x/11.x/172.x) plus one CFCA-owned wildcard domain, so exposure is limited to that specific corporate network rather than the open web.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

zyyizhouv3.2.0.7Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

local native-messaging host (PKI/certificate application)
Updated 20 September 2026ldlimjohgodlchaagdhiljpccoohejbk