CVE-2026-102878 | hangwin mcp-chrome-bridge up to 1.0.31 Native-Server HTTP API cross-domain policy
A vulnerability described as problematic has been identified in hangwin mcp-chrome-bridge up to 1.0.31. The affected element is an unknown function of the component Native-Server HTTP API. The manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is known as CVE-2026-102878. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More