Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Proctorio
Proctorio secure Exam Proctor Extension |
|
| Vendors & Products |
Proctorio
Proctorio secure Exam Proctor Extension |
|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute. | |
| Title | Insufficient Origin Validation in Proctorio Chrome Extension postMessage Handlers | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Hackrate
Published: 2026-02-11T14:49:44.991Z
Updated: 2026-02-11T21:19:08.551Z
Reserved: 2026-02-11T14:45:32.162Z
Link: CVE-2026-2345
Updated: 2026-02-11T21:19:06.078Z
Status : Awaiting Analysis
Published: 2026-02-11T15:16:18.160
Modified: 2026-02-11T15:27:26.370
Link: CVE-2026-2345
No data.