VU#595768: Securly Chrome Extension contains multiple weak encryption and access control vulnerabilities
2026-06-03T20:52:10Z•5875a3a49cc1eb6a1330651de2b544d30c74659c1b69cedd1d995bb4fab452f7
caesar-cipherchrome-extensioncodemirrorcredential-theftdevice-driverhardcoded-keysimproper-authenticationimsinformation-disclosureinsecure-transportintegrity-bypassipseckernel-exploitmissing-access-controlpath-traversalprivilege-escalationrcesipstored-xsssupply-chainunauthenticated-rcevolteweak-cryptographyxsszip-slip
What happened
This feed contains multiple distinct, high-impact vulnerabilities across several products: Securly Chrome Extension (v3.0.7) exposes sensitive filtering data via HTTP, ships hardcoded AES passphrases, and exposes poorly obfuscated hashes allowing unauthenticated access (CVE-2026-8874, -8876, -8878, -8879); Verizon IMS/VoLTE deployments observed SIP signaling without negotiated IPsec integrity protection enabling interception/modification (CVE-2026-10629); Appsmith stored XSS in the SQL editor autocomplete that enables arbitrary JS execution for workspace members (CVE-2026-7299); Collibra Agent
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 5875a3a49cc1eb6a1330651de2b544d30c74659c1b69cedd1d995bb4fab452f7
- Enrichment time
- 2026-06-03T20:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.