Is Symantec Authentication Client Extension safe?

Low risk

Symantec Authentication Client Extension relays PKI commands from any web page to a locally installed native messaging host.

The extension injects a content script on every website (<all_urls>) that listens for CustomEvents dispatched by page JavaScript, then forwards those events to a background script which connects to the Symantec PKI Client native messaging host. Because the content script applies to all sites without restriction, any web page can trigger PKI and authentication operations on the user's locally installed Symantec Authentication Client. The extension also injects a detectable DOM marker into every page, allowing any in-page script to confirm whether the extension is installed.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Broadcom Enterprise Security Groupv100.5.0.109Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 100.5.0.109. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every site you visit

    <all_urls>

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026ahgdclgdhfeingghldkedleghekbfhef