Is CFCA CertEnrollment.ADBC Extension safe?
CFCA CertEnrollment bridges ADBC bank pages to a local native application for certificate-based authentication.
The extension listens for messages exclusively from *.ebank.adbc.com.cn pages and relays them to a locally installed native application via Chrome's native messaging API. The native host name used for each connection is supplied by the calling bank page without validation, meaning any page on the permitted domain can direct the extension to connect to any registered native host by name. No user data is transmitted to remote servers; all communication stays between the browser and the local machine.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.