CVE-2026-94111: Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin
Summary
Tencent BrowserSkill up to version 0.3.0 has a security flaw in its local daemon's WebSocket origin validation (the process that checks if a connection request is from a legitimate source). Attackers can create a fake browser extension that appears legitimate and use it to intercept and alter the page content, DOM (the structure of web page elements), and screenshots that the AI agent receives.
Vulnerability Details
6.6(medium)
EPSS: 0.0%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
local
low
low
none
September 20, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-94111
First tracked: September 20, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%