CVE-2026-102878: mcp-chrome-bridge through 1.0.31 CORS Origin Bypass
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users running mcp-chrome-bridge through version 1.0.31 with its native-server HTTP API accessible to their browser are exposed. A malicious web page can send cross-origin requests to the local server.
What must an attacker do to exploit it?
The attacker needs to induce a user to visit a malicious web page. No attacker privileges are required, and the exploit can then use the origin-validation flaw to bypass CORS restrictions.
What actions could an attacker perform through the vulnerable API?
The attacker can invoke browser automation tools, including executing scripts, reading page content, and capturing screenshots. The reported impact includes high confidentiality and integrity impact.