Is CFCA SecEditCtl.SRCB Extension safe?

Low risk

CFCA SecEditCtl.SRCB Extension bridges pages on srcb.com and shrcb.com to a locally installed native messaging host without validating the host name supplied by the caller.

The extension acts as a native messaging relay for CFCA's secure edit control on SRCB banking pages. When a page on *.srcb.com or *.shrcb.com requests a connection, the extension passes the caller-supplied host name directly to chrome.runtime.connectNative() without checking that it matches the expected host. This means any page within the allowed domains can request a connection to any locally registered native messaging host, not just the intended CFCA one.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

developer.srcbv3.2.0.5Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 17 September 2026ikmbmfkdkoampbhdaknhonadjaofhhnh