Bytedance · Coze Scraper Extension · CVE-2026-96680
**Name of the Vulnerable Software and Affected Versions**
ByteDance Coze Scraper Extension versions prior to 2.0.3
**Description**
An issue exists in the External Message Handler component within the `static/background/index.js` file. The `chrome.runtime.onMessageExternal.addListener()` function fails to properly authorize requests, allowing remote attackers to bypass authorization by manipulating the `body.url`, `paginationConfig`, `xPathConfig`, `body.urls`, or `xPaths` arguments.
**Recommendations**
Update ByteDance Coze Scraper Extension to a version newer than 2.0.2.
As a temporary mitigation, restrict the use of the `chrome.runtime.onMessageExternal.addListener()` function in the `static/background/index.js` file.