CVE 7.5 HIGH

Private Key stored as extractable in browser IndexeDB_CVE-2026-35467

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

Basic Information

ID CVE-2026-35467
Source certcc
Published Apr 2, 2026 at 20:27
Modified Apr 3, 2026 at 13:51

Affected Product

Vendor CERT/CC
Product cveClient/encrypt-storage.js
Affected Versions CERT/CC cveClient/encrypt-storage.js 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.