Skip to content
Threat Feed
high advisory

Origin Validation Error in mcp-chrome-bridge native-server HTTP API

An origin validation vulnerability in mcp-chrome-bridge versions 1.0.31 and earlier allows attackers to bypass CORS and perform unauthorized browser automation actions via malicious web pages.

CVE search metadata

CVE search record: CVE-2026-102878. Severity: high. CVSS: 8.1. KEV: no. Product: Mcp-Chrome-Bridge. Brief: Origin Validation Error in mcp-chrome-bridge native-server HTTP API. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mcp-chrome-bridge-cors/

mcp-chrome-bridge versions up to 1.0.31 contain an origin validation error within the native-server HTTP API. This vulnerability allows an attacker to bypass Cross-Origin Resource Sharing (CORS) restrictions. By hosting a malicious website, an attacker can trick a user's browser into making unauthorized cross-origin requests to the local server process running as part of the bridge application. This flaw enables an attacker to invoke browser automation tools directly, which can result in arbitrary script execution, reading sensitive page content from the browser, or capturing unauthorized screenshots of the user's active browser sessions. This is particularly dangerous for developers who use these tools for local automation, as the bridge inherently has high-privilege access to browser interfaces.

Impact

Successful exploitation allows remote attackers to execute code in the context of the user's browser or exfiltrate sensitive data from open browser tabs. This threatens developers and automated testing environments using mcp-chrome-bridge, as it provides a mechanism for local information theft and persistent browser-based execution via a browser-borne attack vector.

Recommendation

  • Update mcp-chrome-bridge to the latest available version beyond 1.0.31 to patch the origin validation logic.
  • Restrict access to the native-server HTTP API to trusted local origin domains only.
  • Monitor for unauthorized cross-origin traffic initiated from browser-based applications to local server ports where mcp-chrome-bridge may be listening.

Immediate actions

Update all instances of mcp-chrome-bridge beyond version 1.0.31

IT Operations 48h

Mitigations

Review local firewall rules for browser automation tools

immediate Security Operations

CVE-2026-102878