Is CFCA CryptoKit.CIB Extension safe?
CFCA CryptoKit.CIB Extension forwards caller-supplied native host names without validation, allowing any authorized origin to connect to arbitrary native messaging hosts.
The extension acts as a bridge between bank web pages (cib.com.cn, cib.com, firmbank.xyz, and several private IP addresses) and native applications installed on the user's machine. When a page sends a connect request, the extension passes the caller-supplied host name directly to chrome.runtime.connectNative() with no allowlist check. Any origin in the externally_connectable list can specify any native host name and send it arbitrary messages via the extension.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 3.4.1.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging