Is CFCA CryptoKit.Paperless.zybank Extension safe?
CFCA CryptoKit accepts a caller-supplied native host name from bank-domain pages and connects to it without validating it against an allowlist.
The extension bridges web pages on zybank.com.cn and related bank domains to local native messaging hosts for cryptographic operations. When a page sends a 'connect' message, the extension passes the page-supplied host name directly to chrome.runtime.connectNative without checking it against a fixed list of expected hosts. This means a script running on the permitted bank domains could direct the extension to connect to any native messaging host registered on the user's machine, not just the intended CFCA cryptokit application.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 3.4.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging