CVE-2026-8874 Details
Description
Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent implementation of TLS.
A vulnerability in version 3.0.7 of the Securly Chrome Extension allows the download of JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP, using the Fetch API. This inconsistent implementation of TLS exposes sensitive data, as other endpoints in the extension correctly use HTTPS. The Securly Chrome Extension is commonly used on K–12 school-managed Chromebooks to enforce internet safety policies and manage student online activity.
Until a patch is available, administrators can reduce exposure by limiting the extension's use on untrusted networks, deploying school-managed VPNs on affected devices, and monitoring for unusual filtering behavior.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.cert.org/vuls/id/595768 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| securly securly | 3.0.7 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Jun 4, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | New CVE Received | [email protected] |