Is I.CA PKI Service Component safe?

Medium risk

I.CA PKI Service Component accepts cookie-read requests from third-party web pages and forwards retrieved banking-domain cookies to a native host application.

The extension acts as a bridge between web pages and a locally installed PKI application (cz.ica.icapkiservice.host) for digital signing workflows. Pages listed in its externally_connectable configuration can send messages requesting cookies from banking and certificate-authority domains (ica.cz, csob.cz, csob.sk, proebiz.com). Some of those permitted pages—such as digisign.org, eon.com, and circularo.com—are not covered by the extension's own host_permissions, yet can still submit cookie-read requests targeting the banking domains that are covered, with the retrieved cookie values then passed to the native host.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

ICAv2.2.1.0Chrome Web Store
45Risk
Who publishes it

První certifikační autorita, a.s. - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
ICA
Declared legal entity
První certifikační autorita, a.s.
Registered address
Podvinný mlýn 2178/6, Praha 9 190 00, CZ
Registered contact
David Hoření

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 2.2.1.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on ica.cz

    *://*.ica.cz/*

  • Read and change your data on csob.cz

    *://*.csob.cz/*

  • Read and change your data on csob.sk

    *://*.csob.sk/*

  • Read and change your data on proebiz.com

    *://*.proebiz.com/*

  • Read and change your data on localhost

    *://localhost/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Act on the current tab, but only after you click the extension

    activeTab

  • Store data in your browser

    storage

  • Read and change cookies, including the ones that keep you signed in

    cookies

Where it sends data

Destinations our analysis observed I.CA PKI contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • cz.ica.icapkiservice.host

    I.CA PKI sends data to cz.ica.icapkiservice.host. 4 other extensions we have analysed send data here.

Updated 30 September 2026fdolcjnejgbpoadihncaggiicpkhjchl