PT-2026-102894 · Unknown · Mcp-Chrome-Bridge

·

CVE-2026-102878

·

Published

2026-09-29

·

Updated

2026-09-30

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions mcp-chrome-bridge versions prior to 1.0.32
Description An origin validation error exists in the native-server HTTP API that allows attackers to bypass Cross-Origin Resource Sharing (CORS) restrictions. CORS is a security mechanism that restricts web pages from making requests to a different domain than the one that served the page. By crafting malicious web pages, attackers can make cross-origin requests to the local server to invoke browser automation tools, enabling script execution, reading of page content, and screenshot capture.
Recommendations Update mcp-chrome-bridge to version 1.0.32 or later.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102878

Affected Products

Mcp-Chrome-Bridge