Is CFCA SecEditCtl.SRCB Extension safe?
CFCA SecEditCtl.SRCB Extension bridges pages on srcb.com and shrcb.com to a locally installed native messaging host without validating the host name supplied by the caller.
The extension acts as a native messaging relay for CFCA's secure edit control on SRCB banking pages. When a page on *.srcb.com or *.shrcb.com requests a connection, the extension passes the caller-supplied host name directly to chrome.runtime.connectNative() without checking that it matches the expected host. This means any page within the allowed domains can request a connection to any locally registered native messaging host, not just the intended CFCA one.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.