CVE-2026-82809 | vidIQ Vision for YouTube Extension 3.199.0 on Chrome postMessage window.addEventListener vidiqEvent information disclosure
A vulnerability was found in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. It has been classified as problematic. The affected element is the function window.addEventListener of the component postMessage Handler. Performing a manipulation of the argument vidiqEvent results in information disclosure.
This vulnerability is reported as CVE-2026-82809. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor explains: “At this time, vidIQ does not accept security vulnerability submissions, and we do not have a bug bounty program in place.”VulDB Recent EntriesRead More