
Breaking: CVE-2026-102878 scores 8.1 • OpenAI launches $500 Pro tier • Anthropic flags $42B loss • IBM Guardium hit by injection flaw Two minutes of verified tech news. https://t.co/yw1ZXGbHWA
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

Breaking: CVE-2026-102878 scores 8.1 • OpenAI launches $500 Pro tier • Anthropic flags $42B loss • IBM Guardium hit by injection flaw Two minutes of verified tech news. https://t.co/yw1ZXGbHWA

CVE-2026-102878 hits mcp-chrome-bridge through 1.0.31 with CVSS 8.1. Attackers bypass CORS via malicious pages to run scripts, read content, and capture screenshots. Now I'm curious how many local installs remain unpatched. https://thecircuitry.to/article/cve-2026-102878-scores-81-in-mcp-chrome-bridge-through-1031-mun4jon4 https://t.co/Up19pnXGMy