CVE-2026-94111
MEDIUM
NVD
CVSS Score
6.6
Severity
MEDIUM
Published
Sep 20, 2026
Vendor
unknown
Description
Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent.