CVE-2026-8876 PUBLISHED

CVE-2026-8876

Assigner: certcc
Reserved: 18.05.2026 Published: 03.06.2026 Updated: 04.06.2026

Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keyword data and intervention site data.

Product Status

Vendor Securly
Product Securly Chrome Extension
Versions
  • affected from 0 to 3.0.7 (incl.)

References

Problem Types

  • CWE-321