Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 21 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tencent
Tencent browserskill |
|
| Vendors & Products |
Tencent
Tencent browserskill |
Mon, 21 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent. | |
| Title | Tencent BrowserSkill through 0.3.0 Origin Validation Error in Local WebSocket Daemon | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T14:18:11.209Z
Reserved: 2026-09-20T11:41:32.291Z
Link: CVE-2026-94111
Updated: 2026-09-21T14:16:59.050Z
Status : Received
Published: 2026-09-20T12:17:06.787
Modified: 2026-09-21T15:17:38.413
Link: CVE-2026-94111
No data.
OpenCVE Enrichment
Updated: 2026-09-21T19:24:28Z