Is CFCA WebSeal.SRCB Extension safe?

Low risk

CFCA WebSeal.SRCB Extension bridges bank web pages to local native security software via native messaging, accepting the target host name from the calling page without validation.

The extension acts as a relay between pages on srcb.com and shrcb.com (Shenzhen Rural Commercial Bank) and locally installed native messaging hosts used for digital certificate operations. When a bank page requests a connection, the extension passes the caller-supplied host name directly to chrome.runtime.connectNative without checking it against an allowlist. This means a cross-site scripting attack on either bank domain could direct the extension to open a native messaging channel to any installed native application on the user's machine.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

developer.srcbv3.2.0.3Chrome Web Store
20Risk
Who publishes it

developer.srcb - 3 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
developer.srcb

Same store account

3 other listings published from this account, 70k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 3.2.0.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on srcb.com

    http://*.srcb.com/* and 1 more

  • Read and change your data on shrcb.com

    http://*.shrcb.com/* and 1 more

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026logimmpkalbnalilnoioddnkoegggblh