CVE-2026-8881 PUBLISHED

CVE-2026-8881

Assigner: certcc
Reserved: 18.05.2026 Published: 03.06.2026 Updated: 03.06.2026

Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption. MD5 has been broken since 2004 and a single iteration provides no key stretching.

Product Status

Vendor Securly
Product Securly Chrome Extension
Versions
  • affected from 0 to 3.0.7 (incl.)

References

Problem Types

  • CWE-916 Use of Password Hash With Insufficient Computational Effort