PatchSiren cyber security CVE debrief
CVE-2026-94111 Tencent CVE debrief
CVE-2026-94111 debrief based on the supplied source corpus. The CVE record was published on 2026-09-20T12:17:06.787Z and has not been modified since then. The vulnerability affects Tencent BrowserSkill through version 0.3.0, allowing authentication bypass and potential content manipulation. Defenders should verify and mitigate this vulnerability, particularly in deployments using versions through 0.3.0. The CVE record and source item provide details on the authentication bypass vulnerability in Tencent BrowserSkill through 0.3.0, but further verification is required to determine the full scope of affected systems and potential impact.
- Vendor
- Tencent
- Product
- BrowserSkill
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-20
- Original CVE updated
- 2026-09-20
- Advisory published
- 2026-09-20
- Advisory updated
- 2026-09-20
Who should care
Defenders responsible for Tencent BrowserSkill deployments, particularly those using versions through 0.3.0, should assess exposure and prioritize mitigation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify and mitigate the vulnerability.
Why it matters
CVE-2026-94111 is a medium-severity vulnerability in Tencent BrowserSkill that allows authentication bypass and potential content manipulation. Defenders should verify and mitigate this vulnerability, particularly in deployments using versions through 0.3.0.
- Potential interception and manipulation of page content, DOM, and screenshots
- Possible registration of malicious extensions as browser clients
- Required verification of BrowserSkill versions and configurations
- Need for additional authentication and authorization measures
Technical summary
Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent. The vulnerability allows for potential interception and manipulation of page content, DOM, and screenshots. Defenders should prioritize verifying and mitigating the authentication bypass vulnerability in Tencent BrowserSkill through 0.3.0.
Defensive priority
Defenders should prioritize verifying and mitigating the authentication bypass vulnerability in Tencent BrowserSkill through 0.3.0.
Recommended defensive actions
- Verify Tencent BrowserSkill versions through 0.3.0 for potential exposure
- Implement additional authentication and authorization measures for BrowserSkill deployments
- Monitor for and restrict malicious extension registrations
- Review and update BrowserSkill configurations to prevent content interception and manipulation
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The CVE record and source item provide details on the authentication bypass vulnerability in Tencent BrowserSkill through 0.3.0, but further verification is required to determine the full scope of affected systems and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94111 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94111
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94111 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94111
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Tencent/BrowserSkill/blob/cli-v0.3.0/crates/bsk-cli/src/daemon/ws.rs
-
Source reference
Unverified legacy reference
URL: https://github.com/Tencent/BrowserSkill/issues/273
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/tencent-browserskill-through-0.3.0-origin-validation-error-in-local-websocket-daemon
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.