GHSA-x6f2-qp26-2xrhMediumCVSS 6.6

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local...

Published
September 20, 2026
Last Modified
September 20, 2026

🔗 CVE IDs covered (1)

📋 Description

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent.

🔗 References (5)