Is CFCA CryptoKit.TRTCW Extension safe?
CFCA CryptoKit.TRTCW Extension relays native-messaging commands for any page matching one of four bare IP addresses, not a vendor domain.
This extension bridges web pages to a local native application, letting matching pages request cryptographic operations through it. The pages allowed to use this bridge are defined by four hard-coded IP addresses (three private LAN addresses and one public one, over both HTTP and HTTPS) rather than a vendor-controlled domain, and the extension forwards the caller-supplied host name straight to Chrome's native-messaging API without checking it against an expected value. This means any device that a browser resolves to one of those exact addresses can open the same native-messaging channel.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.