Retour à la veille

CVE-2026-94111

Publié : 20 septembre 2026
Modifié : 20 septembre 2026
Lien officiel NVD
Score CVSS
6.6
MEDIUM

Description détaillée

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

Références et Patchs