Description
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).
Published: 2026-06-03
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Version 3.0.7 of the Securly Chrome Extension relies on SHA‑1 hashing to match IWF CSAM URLs (25,020 hashes) and CIPA blocklist entries (12,352 hashes). SHA‑1 is cryptographically weak and vulnerable to collision attacks. An attacker who can generate a hash collision could manipulate the extension’s whitelist logic, causing CSAM or blocked content to be treated as allowed or vice versa. This undermines the extension’s primary purpose of protecting users from disallowed content, potentially exposing children and other users to inappropriate material.

Affected Systems

The vulnerability affects the Securly Chrome Extension, version 3.0.7. No other versions or related products were explicitly mentioned. Administrators using this specific extension version should be aware of the weakness in its hashing mechanism.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable, indicating that no public exploitation data is currently known. The attack likely requires the attacker to craft a specific hash collision, which is computationally intensive and may not be feasible in the near term. Nonetheless, the use of a broken hash algorithm compromises policy enforcement, and the absence of a listed KEV entry does not negate the risk. Organizations should monitor for vendor updates and consider disabling the extension until a patch that replaces SHA‑1 is released.

Generated by OpenCVE AI on June 3, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Securly Chrome Extension to the latest version once the vendor addresses the SHA‑1 weakness.
  • If no patch is available, disable or uninstall the Securly Chrome Extension to prevent compromised content filtering.
  • Monitor Securly’s security advisories and support channels for guidance and any forthcoming fixes.
  • Evaluate alternative content‑filtering solutions that employ secure cryptography to mitigate the risk.

Generated by OpenCVE AI on June 3, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 03 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-327

Wed, 03 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Description Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).
Title CVE-2026-8889
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-06-03T18:15:15.450Z

Reserved: 2026-05-18T20:43:53.154Z

Link: CVE-2026-8889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-03T19:16:39.950

Modified: 2026-06-03T19:16:39.950

Link: CVE-2026-8889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T20:30:36Z

Weaknesses