Description
Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Authentication Bypass leading to data manipulation
Action: Update
AI Analysis

Impact

The vulnerability lies in BrowserSkill's local WebSocket daemon, where the origin validation accepts any chrome-extension origin whose 32-character string falls within the a-p range. This is a CWE-346 vulnerability that allows an attacker to register a malicious extension as a browser client and intercept, alter, or inject content into the page, DOM, and screenshots that the AI agent receives, thereby compromising data integrity and confidentiality.

Affected Systems

Tencent BrowserSkill version 0.3.0 and earlier are affected. No other versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. No EPSS score is available, so the exploitation probability is currently unknown, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local; it requires an attacker who can run the BrowserSkill daemon and install a malicious chrome extension, which could then bind to the daemon’s WebSocket and hijack the AI agent’s traffic.

Generated by OpenCVE AI on September 20, 2026 at 13:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Prioritize upgrading BrowserSkill to the latest version once an official fix is released.
  • If an upgrade is not yet available, disable or uninstall any suspicious or non‑trusted chrome extensions that may serve as browser clients.
  • Configure or restrict the local WebSocket daemon to accept origins only from whitelisted, verified extensions, or consider disabling the daemon if not needed.

Generated by OpenCVE AI on September 20, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent.
Title Tencent BrowserSkill through 0.3.0 Origin Validation Error in Local WebSocket Daemon
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T11:56:07.027Z

Reserved: 2026-09-20T11:41:32.291Z

Link: CVE-2026-94111

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-20T12:17:06.787

Modified: 2026-09-20T12:17:06.787

Link: CVE-2026-94111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:00:26Z

Weaknesses