CVE-2026-94111: Tencent BrowserSkill through 0.3.0 Origin Validation Error in Local WebSocket Daemon
Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs the ability to register a malicious browser extension. The vulnerable local WebSocket daemon accepts a chrome-extension origin when its extension identifier is 32 characters using only letters a through p.
Which deployments are exposed?
Tencent BrowserSkill versions through 0.3.0 are affected. Exposure depends on the local daemon being reachable by a browser extension and accepting the attacker-controlled extension origin.
What could a successful attacker do?
A malicious extension can register as a browser client and intercept or manipulate page content, DOM data, and screenshots returned to the AI agent.