Origin Validation Error in mcp-chrome-bridge native-server HTTP API
An origin validation vulnerability in mcp-chrome-bridge versions 1.0.31 and earlier allows attackers to bypass CORS and perform unauthorized browser automation actions via malicious web pages.
CVE search metadata
CVE search record: CVE-2026-102878. Severity: high. CVSS: 8.1. KEV: no. Product: Mcp-Chrome-Bridge. Brief: Origin Validation Error in mcp-chrome-bridge native-server HTTP API. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mcp-chrome-bridge-cors/
mcp-chrome-bridge versions up to 1.0.31 contain an origin validation error within the native-server HTTP API. This vulnerability allows an attacker to bypass Cross-Origin Resource Sharing (CORS) restrictions. By hosting a malicious website, an attacker can trick a user's browser into making unauthorized cross-origin requests to the local server process running as part of the bridge application. This flaw enables an attacker to invoke browser automation tools directly, which can result in arbitrary script execution, reading sensitive page content from the browser, or capturing unauthorized screenshots of the user's active browser sessions. This is particularly dangerous for developers who use these tools for local automation, as the bridge inherently has high-privilege access to browser interfaces.
Impact
Successful exploitation allows remote attackers to execute code in the context of the user's browser or exfiltrate sensitive data from open browser tabs. This threatens developers and automated testing environments using mcp-chrome-bridge, as it provides a mechanism for local information theft and persistent browser-based execution via a browser-borne attack vector.
Recommendation
- Update mcp-chrome-bridge to the latest available version beyond 1.0.31 to patch the origin validation logic.
- Restrict access to the native-server HTTP API to trusted local origin domains only.
- Monitor for unauthorized cross-origin traffic initiated from browser-based applications to local server ports where mcp-chrome-bridge may be listening.
Immediate actions
Update all instances of mcp-chrome-bridge beyond version 1.0.31
Mitigations
Review local firewall rules for browser automation tools
CVE-2026-102878