Impact
Affected web sites can trigger Dark Reader’s image inversion pipeline to make unauthenticated requests to icon‑like bitmap resources served by a locally running web server. This action supersedes the typical website‑to‑server boundary, allowing a site to read data that resides on a local network device. The vulnerability leads to limited information disclosure linked to the requested resource, such as presence of a particular file or service metadata. The weakness is rooted in improper handling of public‑like HTTPS URLs that flag resources for inversion, enabling the extension to perform requests it normally would not be authorized to make.
Affected Systems
The problem exists in the darkreader:darkreader browser extension for all browsers prior to version 4.9.126 for Firefox users and prior to 4.9.128 for users of other browsers. The npm package used for website integration is not impacted. Users who have the extension installed and visit sites that trigger inversion of images will be affected.
Risk and Exploitability
The CVSS score of 3.4 indicates moderate severity, while the EPSS score is not available, suggesting no current data on exploit prevalence. The vulnerability is not listed in CISA’s KEV catalog, and the attack requires only a malicious or compromised website that employs a public‑like HTTPS URL that the extension will invert. Although the exploitation path is straightforward, the impact is limited to disclosed information on local servers, and the window of opportunity is the browsing session in which the site triggers the inversion.
OpenCVE Enrichment