PT-2026-95967 · Tencent · Browserskill
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Tencent BrowserSkill versions prior to 0.3.1
Description
An authentication bypass exists in the local daemon WebSocket origin validation. The system incorrectly accepts any
chrome-extension origin consisting of 32 characters within the range a-p. This allows an attacker to register a malicious extension as a browser client to intercept and manipulate page content, the Document Object Model (DOM), and screenshots returned to the AI agent.Recommendations
Update Tencent BrowserSkill to a version newer than 0.3.0.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Browserskill