CVE-2026-102878

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-29: 1Mentions · 2026-09-30: 109-2909-30
Referenced assets1 URL
Full discourse2 posts
  • The Circuitry@thecircuitry_

    Breaking: CVE-2026-102878 scores 8.1 • OpenAI launches $500 Pro tier • Anthropic flags $42B loss • IBM Guardium hit by injection flaw Two minutes of verified tech news. https://t.co/yw1ZXGbHWA

    0000021
    37 followersView on X
  • The Circuitry@thecircuitry_

    CVE-2026-102878 hits mcp-chrome-bridge through 1.0.31 with CVSS 8.1. Attackers bypass CORS via malicious pages to run scripts, read content, and capture screenshots. Now I'm curious how many local installs remain unpatched. https://thecircuitry.to/article/cve-2026-102878-scores-81-in-mcp-chrome-bridge-through-1031-mun4jon4 https://t.co/Up19pnXGMy

    0000017
    37 followersView on X

Explore more