CVE-2026-82810

A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service Worker. Executing a manipulation of the argument sender.id can lead to information disclosure. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 17:17

Updated : 2026-09-02 15:17


NVD link : CVE-2026-82810

Mitre link : CVE-2026-82810

CVE.ORG link : CVE-2026-82810


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control