Is FastAccess Face Recognition Web Login safe?

Clean risk

FastAccess Face Recognition Web Login reads login form credentials on all websites and forwards them to a locally-installed native application for face-recognition SSO.

On every page load, the extension's content script monitors username and password fields across all frames on all HTTP and HTTPS sites. When credentials are entered, the extension hex-encodes them and sends them to a background page, which relays them over a persistent native messaging channel to a native host named com.google.chrome.fa.sso. The native host stores the credentials and returns them for autofill when the user authenticates via face recognition.

Sensible Visionv1.0.0.96Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.0.0.96. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • See the address and title of every tab you have open

    tabs

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Where it sends data

Destinations our analysis observed FastAccess SSO contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • com.google.chrome.fa.sso (local native host)

    FastAccess SSO sends data to com.google.chrome.fa.sso (local native host). Named as a recipient in this extension's own analysis.

Updated 21 September 2026bcebepcbopnpbdhimpgfbbdkbimaoafn