Is CFCA CryptoKit.YZW Extension safe?

Low risk

CFCA CryptoKit.YZW Extension accepts a caller-supplied native messaging host name, allowing any whitelisted page to connect to any native application on the user's machine.

The extension acts as a bridge between web pages on a fixed set of Chinese financial domains (yzw.cn, cscec.com, paic.com.cn, cscec3b.com.cn, 3jyx.cn) and locally installed native applications via Chrome's native messaging API. When a page sends a connect request, the extension passes the page-supplied host name directly to chrome.runtime.connectNative() without validating it against any allowlist, and then forwards arbitrary message payloads verbatim to the connected host. Any page on the whitelisted domains can exploit this to reach any native messaging host registered on the user's system, not just the intended CFCA cryptographic application.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

developerv3.4.0.5Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026gmcdjblnokdfaicekifdgkpmakafenho