Is Turbo Sync safe?

Low risk

Turbo Sync sends users to a plaintext HTTP page to download the native messaging host installer, enabling network interception.

When installed or when the user clicks the installation button, the extension opens a tab to http://deploiement.turbosa.banquepopulaire.fr/turbosync/ — an unencrypted HTTP URL. This page serves the installer for the fr.turbosa.turbosync native messaging host. A network-positioned attacker can intercept the HTTP response and substitute a modified installer, which would then be granted native messaging access to the extension.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Turbo S.A - Groupe BPCEv1.406Chrome Web Store
20Risk
Who publishes it

TURBO SA - 2 other listings from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Turbo S.A - Groupe BPCE
Declared legal entity
TURBO SA
Registered address
86 RUE DU DOME, BATIMENT A, BOULOGNE BILLANCOURT 92100, FR
Registered contact
Yann RAOUL

Same store account

2 other listings published from this account, 130k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 1.406. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

Updated 30 September 2026hkbadnaeddlmalappbcocohapdfdlnno