PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94111 Tencent CVE debrief

CVE-2026-94111 debrief based on the supplied source corpus. The CVE record was published on 2026-09-20T12:17:06.787Z and has not been modified since then. The vulnerability affects Tencent BrowserSkill through version 0.3.0, allowing authentication bypass and potential content manipulation. Defenders should verify and mitigate this vulnerability, particularly in deployments using versions through 0.3.0. The CVE record and source item provide details on the authentication bypass vulnerability in Tencent BrowserSkill through 0.3.0, but further verification is required to determine the full scope of affected systems and potential impact.

Vendor
Tencent
Product
BrowserSkill
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-20
Original CVE updated
2026-09-20
Advisory published
2026-09-20
Advisory updated
2026-09-20

Who should care

Defenders responsible for Tencent BrowserSkill deployments, particularly those using versions through 0.3.0, should assess exposure and prioritize mitigation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify and mitigate the vulnerability.

Why it matters

CVE-2026-94111 is a medium-severity vulnerability in Tencent BrowserSkill that allows authentication bypass and potential content manipulation. Defenders should verify and mitigate this vulnerability, particularly in deployments using versions through 0.3.0.

  • Potential interception and manipulation of page content, DOM, and screenshots
  • Possible registration of malicious extensions as browser clients
  • Required verification of BrowserSkill versions and configurations
  • Need for additional authentication and authorization measures

Technical summary

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent. The vulnerability allows for potential interception and manipulation of page content, DOM, and screenshots. Defenders should prioritize verifying and mitigating the authentication bypass vulnerability in Tencent BrowserSkill through 0.3.0.

Defensive priority

Defenders should prioritize verifying and mitigating the authentication bypass vulnerability in Tencent BrowserSkill through 0.3.0.

Recommended defensive actions

  • Verify Tencent BrowserSkill versions through 0.3.0 for potential exposure
  • Implement additional authentication and authorization measures for BrowserSkill deployments
  • Monitor for and restrict malicious extension registrations
  • Review and update BrowserSkill configurations to prevent content interception and manipulation
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record and source item provide details on the authentication bypass vulnerability in Tencent BrowserSkill through 0.3.0, but further verification is required to determine the full scope of affected systems and potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94111 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94111

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94111 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94111

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.