Impact
The vulnerability lies in BrowserSkill's local WebSocket daemon, where the origin validation accepts any chrome-extension origin whose 32-character string falls within the a-p range. This is a CWE-346 vulnerability that allows an attacker to register a malicious extension as a browser client and intercept, alter, or inject content into the page, DOM, and screenshots that the AI agent receives, thereby compromising data integrity and confidentiality.
Affected Systems
Tencent BrowserSkill version 0.3.0 and earlier are affected. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. No EPSS score is available, so the exploitation probability is currently unknown, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local; it requires an attacker who can run the BrowserSkill daemon and install a malicious chrome extension, which could then bind to the daemon’s WebSocket and hijack the AI agent’s traffic.
OpenCVE Enrichment