Is CFCA CertEnrollment.CRBank Extension safe?

Clean risk

CFCA CertEnrollment.CRBank Extension relays crbank.com.cn page requests to a native messaging host with no in-handler sender check.

This extension bridges crbank.com.cn banking pages to a native messaging host installed locally on the user's machine, supporting certificate enrollment and related security operations. Pages on crbank.com.cn can ask it to connect to a named native host and then forward arbitrary message payloads to that host's process; the code itself performs no additional sender check, relying only on Chrome's enforcement of the manifest's externally_connectable scope.

0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

locally installed CFCA native messaging host
Updated 20 September 2026abamnhdofgnpabgabijnefnjhboddgdf