What happened
NVD published CVE-2026-102878 (CVSS 8.1 v3.1 / 8.6 v4.0) on 2026-09-29. mcp-chrome-bridge's native-server HTTP API fails origin validation, so any website can bypass CORS and drive the local browser-automation MCP server, including script execution against the victim's browser. CISA SSVC marks exploitation 'poc'.
Why it matters
Browser-use / Chrome-control MCP servers are the remote-control surface for AI coding and web agents on endpoints. An origin-validation flaw turns a routine web visit into drive-by control of the user's AI browser agent — reading the active page (credentials, tokens), running scripts, and taking screenshots — a classic browsing-agent attack vector (CSRF-to-MCP class) against a locally listened MCP server.
Attack vector
Attacker hosts a malicious web page that makes cross-origin requests to the local native-server HTTP API (CORS/origin validation error, CWE-346), invoking browser-automation tools — script execution, reading page content, capturing screenshots — in the victim's browser context.
Affected systems
hangwin mcp-chrome-bridge (npm) through 1.0.31
Mitigation
Restrict/listen on loopback only, add strict Origin+Host allowlisting on the native-server HTTP API, and upgrade mcp-chrome-bridge; track issue #384 for the vendor fix.