Is SET-RN Security Module safe?
SET-RN Security Module relays caller-supplied URLs to a locally installed native host app without URL validation.
The extension exposes a JavaScript API to pages on *.set.rn.gov.br that allows them to proxy HTTP requests through a native host application (br.gov.rn.set.host) installed on the user's machine. The destination URL is forwarded verbatim from the page to the native host without restriction, meaning any page on the permitted origin can direct the native app to make requests to arbitrary URLs. Access is limited to pages matching the extension's externally_connectable scope.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on set.rn.gov.br
*://*.set.rn.gov.br/*
Read and change your data on localhost
*://localhost/*
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Read and change cookies, including the ones that keep you signed in
cookies
Where it sends data
Destinations our analysis observed SET-RN Security Module contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- br.gov.rn.set.host (local native host app)
SET-RN Security Module sends data to br.gov.rn.set.host (local native host app). Named as a recipient in this extension's own analysis.