CVE Explorer
CVE-2026-8879
Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContentScripts() at runtime. This script is NOT declared in manifest.json and bypasses Chrome Web Store static security review. It runs on all URLs and immediately hides all page content, creates a full-page overlay, pauses all videos, and only restores content when the service worker confirms the page passes filtering. If Securly's servers are unreachable, pages
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-829","description":"CWE-829 Inclusion of Functionality from Untrusted Control Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:432d04dfdc0ae22a00c51219ae44cde5b203da8fed33293c6d94985fcdff4eac · sha256:e9b390ab71e7dd28… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"CWE-829 Inclusion of Functionality from Untrusted Control Sphere","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:432d04dfdc0ae22a00c51219ae44cde5b203da8fed33293c6d94985fcdff4eac · sha256:e9b390ab71e7dd28… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"Securly Chrome Extension","vendor":"Securly","versions":[{"lessThanOrEqual":"3.0.7","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:432d04dfdc0ae22a00c51219ae44cde5b203da8fed33293c6d94985fcdff4eac · sha256:e9b390ab71e7dd28… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:432d04dfdc0ae22a00c51219ae44cde5b203da8fed33293c6d94985fcdff4eac · sha256:e9b390ab71e7dd28… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-829","description":"CWE-829 Inclusion of Functionality from Untrusted Control Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:432d04dfdc0ae22a00c51219ae44cde5b203da8fed33293c6d94985fcdff4eac · sha256:e9b390ab71e7dd28… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"CWE-829 Inclusion of Functionality from Untrusted Control Sphere","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:432d04dfdc0ae22a00c51219ae44cde5b203da8fed33293c6d94985fcdff4eac · sha256:e9b390ab71e7dd28… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://kb.cert.org/vuls/id/595768"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:432d04dfdc0ae22a00c51219ae44cde5b203da8fed33293c6d94985fcdff4eac · sha256:e9b390ab71e7dd28… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.