PT-2026-46048 · Securly · Securly Chrome Extension
CVSS v3.1
7.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Securly Chrome Extension version 3.0.7
Description
The extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP using the Fetch API. This represents an inconsistent implementation of Transport Layer Security (TLS), as other endpoints within the same extension correctly utilize HTTPS to fetch IWF and CIPA data.
Recommendations
Update Securly Chrome Extension version 3.0.7 to a version that ensures all data is fetched over HTTPS.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Securly Chrome Extension