Is CFCA CertEnrollment.CZCB Extension safe?
CFCA CertEnrollment.CZCB Extension bridges web pages on czcb.com.cn to a local native PKI application using caller-supplied host names.
The extension acts as a native messaging relay for CFCA certificate enrollment on China Construction Bank (czcb.com.cn) pages. Any czcb.com.cn page—including those served over HTTP—can instruct the extension to connect to an arbitrary native messaging host name, since the host value is taken directly from the external message without validation against a fixed allowlist. No user data is transmitted to remote servers; all communication is between the web page and a locally installed native application.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 3.2.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging