{"id":"CVE-2026-94111","published":"2026-09-20T12:17:06.787","lastModified":"2026-09-21T15:17:38.413","description":"Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent.","cvssScore":6.6,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","cwes":["CWE-346"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Tencent/BrowserSkill/blob/cli-v0.3.0/crates/bsk-cli/src/daemon/ws.rs#L36-L57","tags":[]},{"url":"https://github.com/Tencent/BrowserSkill/issues/273","tags":[]},{"url":"https://www.vulncheck.com/advisories/tencent-browserskill-through-0.3.0-origin-validation-error-in-local-websocket-daemon","tags":[]}],"exploitRefs":[{"url":"https://github.com/Tencent/BrowserSkill/blob/cli-v0.3.0/crates/bsk-cli/src/daemon/ws.rs#L36-L57","tags":[]},{"url":"https://github.com/Tencent/BrowserSkill/issues/273","tags":[]}],"hasPoc":true,"ai":null}