{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amcp-chrome-bridgemcp-chrome-bridge/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mcp-chrome-bridge:mcp-chrome-bridge:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-102878"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","browser-security","cors-bypass","mcp-chrome-bridge"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003emcp-chrome-bridge versions up to 1.0.31 contain an origin validation error within the native-server HTTP API. This vulnerability allows an attacker to bypass Cross-Origin Resource Sharing (CORS) restrictions. By hosting a malicious website, an attacker can trick a user's browser into making unauthorized cross-origin requests to the local server process running as part of the bridge application. This flaw enables an attacker to invoke browser automation tools directly, which can result in arbitrary script execution, reading sensitive page content from the browser, or capturing unauthorized screenshots of the user's active browser sessions. This is particularly dangerous for developers who use these tools for local automation, as the bridge inherently has high-privilege access to browser interfaces.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to execute code in the context of the user's browser or exfiltrate sensitive data from open browser tabs. This threatens developers and automated testing environments using mcp-chrome-bridge, as it provides a mechanism for local information theft and persistent browser-based execution via a browser-borne attack vector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate mcp-chrome-bridge to the latest available version beyond 1.0.31 to patch the origin validation logic.\u003c/li\u003e\n\u003cli\u003eRestrict access to the native-server HTTP API to trusted local origin domains only.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized cross-origin traffic initiated from browser-based applications to local server ports where mcp-chrome-bridge may be listening.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T20:30:04Z","date_published":"2026-09-29T20:30:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mcp-chrome-bridge-cors/","summary":"An origin validation vulnerability in mcp-chrome-bridge versions 1.0.31 and earlier allows attackers to bypass CORS and perform unauthorized browser automation actions via malicious web pages.","title":"Origin Validation Error in mcp-chrome-bridge native-server HTTP API","url":"https://feed.craftedsignal.io/briefs/2026-09-mcp-chrome-bridge-cors/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:mcp-Chrome-Bridge:mcp-Chrome-Bridge:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}