PT-2026-46053 · Google Chrome · Securly Chrome Extension

·

CVE-2026-8888

·

Published

2026-06-03

·

Updated

2026-06-05

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Securly Chrome Extension version 3.0.7
Description The software downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions using the new RegExp() function without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, which is a state where a regular expression engine takes an exponential amount of time to determine if a string matches a pattern, resulting in a denial of service for all browsing.
Recommendations Update Securly Chrome Extension to a version newer than 3.0.7. As a temporary workaround, restrict the use of the new RegExp() function for processing server-provided patterns until a patch is applied.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8888

Affected Products

Securly Chrome Extension