Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jg8r-xqh5-556r

Опубликовано: 03 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContentScripts() at runtime. This script is NOT declared in manifest.json and bypasses Chrome Web Store static security review. It runs on all URLs and immediately hides all page content, creates a full-page overlay, pauses all videos, and only restores content when the service worker confirms the page passes filtering. If Securly's servers are unreachable, pages remain indefinitely hidden.

Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContentScripts() at runtime. This script is NOT declared in manifest.json and bypasses Chrome Web Store static security review. It runs on all URLs and immediately hides all page content, creates a full-page overlay, pauses all videos, and only restores content when the service worker confirms the page passes filtering. If Securly's servers are unreachable, pages remain indefinitely hidden.

EPSS

Процентиль: 30%
0.00374
Низкий

7.5 High

CVSS3

Дефекты

CWE-829

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContentScripts() at runtime. This script is NOT declared in manifest.json and bypasses Chrome Web Store static security review. It runs on all URLs and immediately hides all page content, creates a full-page overlay, pauses all videos, and only restores content when the service worker confirms the page passes filtering. If Securly's servers are unreachable, pages remain indefinitely hidden.

EPSS

Процентиль: 30%
0.00374
Низкий

7.5 High

CVSS3

Дефекты

CWE-829