Is CFCA CertEnrollment.Hebbank Extension safe?
The extension lets any hebbank.com page connect to an arbitrary native messaging host on the user's OS without validation.
CFCA CertEnrollment.Hebbank Extension bridges hebbank.com pages to native applications via Chrome's native messaging API. Any page on *.hebbank.com can supply a caller-controlled host name, which the extension passes directly to chrome.runtime.connectNative() with no allowlist or validation check. This allows a hebbank.com page to connect to any native messaging host installed on the user's system and relay arbitrary messages to it.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 3.2.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging