Is CFCA CertEnrollment.SRCB Extension safe?
CFCA CertEnrollment.SRCB Extension bridges SRCB bank pages to locally installed native messaging hosts without validating the host name.
The extension acts as a native messaging relay for pages on *.srcb.com and *.shrcb.com, passing the caller-supplied host name directly to chrome.runtime.connectNative without checking it against an allowlist. Any page on those domains can direct the extension to connect to any native messaging host registered on the user's system and forward arbitrary JSON payloads to it. No user data is transmitted externally — the risk is limited to the local system.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itdeveloper.srcb - 3 other listings from the same operator, none carrying a finding
developer.srcb - 3 other listings from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
3 other listings published from this account, 70k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 3.2.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on srcb.com
http://*.srcb.com/* and 1 more
Read and change your data on shrcb.com
http://*.shrcb.com/* and 1 more
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging