CVE-2026-82813
A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the argument t/c/r results in insufficient verification of data authenticity. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.
Debolezza
A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the argument t/c/r results in insufficient verification of data authenticity. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.
Riferimenti
- https://github.com/xryj920/chrome_extensions/blob/main/BEN%20Group%2C%20Inc.%20TubeBuddy%20for%20YouTube%205.8.4%20allows%20authentication%20token%20overwrite%20through%20an%20unauthenticated%20redirect%20URL%20handler
- https://vuldb.com/cve/CVE-2026-82813
- https://vuldb.com/submit/875303
- https://vuldb.com/vuln/397231
- https://vuldb.com/vuln/397231/cti
Trova il bug prima di un attaccante.
Accedi con GitHub e avvia il tuo primo audit in meno di un minuto. Il piano gratuito non richiede carta di credito.