PT-2026-95967 · Tencent · Browserskill

·

CVE-2026-94111

·

Published

2026-09-20

·

Updated

2026-09-20

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tencent BrowserSkill versions prior to 0.3.1
Description An authentication bypass exists in the local daemon WebSocket origin validation. The system incorrectly accepts any chrome-extension origin consisting of 32 characters within the range a-p. This allows an attacker to register a malicious extension as a browser client to intercept and manipulate page content, the Document Object Model (DOM), and screenshots returned to the AI agent.
Recommendations Update Tencent BrowserSkill to a version newer than 0.3.0.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94111

Affected Products

Browserskill