PT-2026-102894 · Unknown · Mcp-Chrome-Bridge
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
mcp-chrome-bridge versions prior to 1.0.32
Description
An origin validation error exists in the native-server HTTP API that allows attackers to bypass Cross-Origin Resource Sharing (CORS) restrictions. CORS is a security mechanism that restricts web pages from making requests to a different domain than the one that served the page. By crafting malicious web pages, attackers can make cross-origin requests to the local server to invoke browser automation tools, enabling script execution, reading of page content, and screenshot capture.
Recommendations
Update mcp-chrome-bridge to version 1.0.32 or later.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Chrome-Bridge