CVE-2026-19992General

LOWCVSS 1.3 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-17: 3Technical Details · 2026-08-17: 108-17
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-19992 A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the compon… https://www.cve.org/CVERecord?id=CVE-2026-19992 ----- Traducción: Se ha encontrado u… https://infoflow.cloud`

    Post summary

    The excerpt announces that CVE-2026-19992 was identified in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to version 1.4.35 on Chrome, but offers no technical details, PoC, exploit, or patch information.

    0000026
    100 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-19992 A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the compon… https://www.cve.org/CVERecord?id=CVE-2026-19992

    Post summary

    CVE-2026-19992 is cited but the post offers no substantive details, PoC, patch notes, or exploitation evidence.

    00000971
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-19992 Information Disclosure in DualSafe Password Manager Extension (Chrome) Up To 1.4.35 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19992

    Post summary

    An information disclosure vulnerability in DualSafe Password Manager Chrome extension (up to version 1.4.35) has been reported, but no PoC, exploit, active exploitation, patch, or false‑positive claim is present in the text.

    00000115
    4.1K followersView on X

Explore more