Is CFCA JJCCB V3 Extension safe?
CFCA JJCCB V3 Extension bridges four Chinese bank sites to a local PKI native host, reachable over unencrypted http:// too.
This extension relays messages between web pages on jjccb.com, eqianjin.com.cn, jjebank.cn and jycbank.com and native desktop programs (com.cfca.seceditctl.jjccb, com.cfca.cryptokit.jjccb, com.cfca.certenrollment.jjbank) that handle digital certificate and signing operations for online banking. Its manifest lists http:// alongside https:// for these bank domains, so the same page-to-native-host messaging works even if a page loads over plain HTTP. This is a low-severity, unconfirmed finding rather than a demonstrated exploit.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.