SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-82810

LOW · CVSS 3.3 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The 2FA Authenticator Extension for Chrome is vulnerable due to a weakness in the Background Service Worker, specifically in the chrome.runtime.onMessageExternal.addListener function. This flaw allows an attacker with local access to manipulate the sender.id argument, potentially leading to information disclosure. Users of this extension, particularly those managing sensitive data, should prioritize applying any available updates to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82810
Severity
LOW
CVSS
3.3
EPSS
0.10%
Chrome

Original NVD Description

A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service Worker. Executing a manipulation of the argument sender.id can lead to information disclosure. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.