Is CFCA CertEnrollment.UD Extension safe?

Low risk

CFCA CertEnrollment.UD Extension bridges CFCA web pages to native messaging hosts without validating the caller-supplied host name.

The extension acts as a native messaging relay for CFCA certificate-enrollment pages (cs.cfca.com.cn and cstest.cfca.com.cn). When a page sends a connect action, the extension passes the caller-supplied host string directly to chrome.runtime.connectNative with no allowlist check. Any page served from the two permitted origins can therefore instruct the extension to open a native messaging channel to any registered native application on the user's machine.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

CFCAv3.2.0.3Chrome Web Store
20Risk
Who publishes it

CFCA - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
CFCA
Registered address
嘉捷企业汇2号楼, 北京 100176, 中国

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.2.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on cs.cfca.com.cn

    https://cs.cfca.com.cn/*

  • Read and change your data on cstest.cfca.com.cn

    https://cstest.cfca.com.cn/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026felgelgjfpfbikigoijcehkgfkhofpol