PT-2026-46051 · Google Chrome · Securly Chrome Extension
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Securly Chrome Extension version 3.0.7
Description
The software dynamically registers
content13.min.js as a content script at runtime using the chrome.scripting.registerContentScripts() function. Because this script is not declared in the manifest.json file, it bypasses the Chrome Web Store static security review. The script executes on all URLs, hiding all page content, creating a full-page overlay, and pausing all videos. Content is only restored after the service worker confirms the page passes filtering; however, if the servers are unreachable, the pages remain hidden indefinitely.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Securly Chrome Extension