VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-94111

CVE-2026-94111: Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin

Published Sep 20, 2026 CVSS 6.9

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent.

Affected AI Products

ai agent
Get the weekly digest. Every Monday: top AI security stories of the week. Free.