Is CFCA CryptoKit.SDRCB Extension safe?

Low risk

CFCA CryptoKit.SDRCB Extension bridges sdebank.com pages to local native messaging hosts without validating the host name supplied by the caller.

The extension listens for external messages from sdebank.com pages and a specific IP address, then opens a native messaging port to whichever host name the calling page provides. No allowlist restricts which native hosts can be targeted, so any sdebank.com page can instruct the extension to connect to an arbitrary installed native messaging host and relay function calls to it. The extension has no outbound network traffic of its own; all data movement passes through the local native messaging channel.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

sdebank2020v3.4.0.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.4.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 21 September 2026cddofafgecbaiedcjjhmfiojofcbpknn