CVE 3.6 LOW

Insufficient Origin Validation in Proctorio Chrome Extension postMessage Handlers_CVE-2026-2345

3.6 / 10
LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Description

Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute.

Basic Information

ID CVE-2026-2345
Source Hackrate
Published Feb 11, 2026 at 14:49

Affected Product

Vendor Proctorio
Product Secure Exam Proctor Extension
Version 1.5.25220.33
Affected Versions Proctorio Secure Exam Proctor Extension 1.5.25220.33

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.