Is Thales Smart Card Bridge safe?
Thales Smart Card Bridge relays smart card commands from any website to a native host via an unguarded CustomEvent channel.
The extension's content script runs on every HTTP and HTTPS page and listens for 'thalesScBridgeWebPageEvent' CustomEvent messages. Any web page can dispatch these events to forward arbitrary payloads through the extension's background service worker to the native host 'com.thalesesecurity.chrome.smartcardbridge', with responses returned to the page. Additionally, any page can detect the extension's presence and smart card reader availability by sending a 'ping' event and receiving a 'pong' response.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itTHALES DIS CPL USA, INC. - no other listings under this identity
THALES DIS CPL USA, INC. - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.0.6. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging