Is CFCA CertEnrollment.LNWL Extension safe?

Low risk

CFCA CertEnrollment.LNWL Extension exposes an unguarded externally_connectable bridge that lets any webpage connect to and send arbitrary messages to native hosts on the user's system.

The extension accepts external messages from all web origins without validating the sender's identity or origin. Any webpage that knows the extension ID can invoke chrome.runtime.connectNative() with an attacker-supplied host name, then relay arbitrary payloads to that native host through the established port. No authorization check exists at any stage of the message path.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

cfcatechv3.2.0.3Chrome Web Store
20Risk
Who publishes it

cfcatech - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
cfcatech

Same store account

1 other listing published from this account, 4k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.2.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026ifananbfidanobfcdecoilnkjeogjjfn