Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 11 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute. | |
| Title | Insufficient Origin Validation in Proctorio Chrome Extension postMessage Handlers | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Hackrate
Published:
Updated: 2026-02-11T14:49:44.991Z
Reserved: 2026-02-11T14:45:32.162Z
Link: CVE-2026-2345
No data.
Status : Awaiting Analysis
Published: 2026-02-11T15:16:18.160
Modified: 2026-02-11T15:27:26.370
Link: CVE-2026-2345
No data.
OpenCVE Enrichment
No data.
Weaknesses