Is CFCA CryptoKit.ChinaTRC_V3 Extension safe?
CFCA CryptoKit relays a caller-named native messaging host and payload to it, with no allowlist check.
Pages on the extension's permitted intranet and *.chinatrc.com.cn origins can tell it which native messaging host to connect to and what to send, and the extension forwards that host name and payload to chrome.runtime.connectNative() without checking either against a fixed vendor host list. Many of those permitted origins are plaintext HTTP with no HTTPS counterpart, so the native-messaging bridge is reachable and driveable from unencrypted internal-network pages.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.