CVE-2026-102878: Hangwin Mcp-Chrome-Bridge
High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.
Affected products
- Hangwin Mcp-Chrome-Bridge: up to and including 1.0.31
Published 2026-09-29. Last modified 2026-09-30.