Impact
The Toggl Track Extension 4.11.16 contains an origin validation flaw in its postMessage handler. The flaw allows an attacker to forge session‑state messages that the extension will accept, enabling the injection of unauthorized payloads. This can lead to a compromise of the user’s session data, potentially allowing an attacker to hijack activities, alter time entries, or steal sensitive information recorded in the extension.
Affected Systems
Toggl OÜ Toggl Track Extension version 4.11.16 is affected. The vulnerability is specific to this browser extension and does not impact the Toggl web application or other products.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk, and the EPSS score is currently not available, but the vulnerability is publicly disclosed and could be exploited remotely via malicious web content or scripts. The vulnerability is not listed in CISA's KEV catalog, yet the lack of vendor responsiveness increases the likelihood that users remain exposed. Attackers could send crafted postMessage data from any origin to the extension, bypassing origin checks and injecting forged messages.
OpenCVE Enrichment