Is CFCA CertEnrollment.LNWL Extension safe?
CFCA CertEnrollment.LNWL Extension exposes an unguarded externally_connectable bridge that lets any webpage connect to and send arbitrary messages to native hosts on the user's system.
The extension accepts external messages from all web origins without validating the sender's identity or origin. Any webpage that knows the extension ID can invoke chrome.runtime.connectNative() with an attacker-supplied host name, then relay arbitrary payloads to that native host through the established port. No authorization check exists at any stage of the message path.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itcfcatech - 1 other listing from the same operator, none carrying a finding
cfcatech - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 4k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 3.2.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
http://*/*
Read and change your data on every secure site you visit
https://*/*
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging