CVE-2026-2345

low-risk
Published 2026-02-11

Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute.

Do I need to act?

-
0.01% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.6/10 Low
LOCAL / HIGH complexity
14
/ 100
low-risk
Severity 9/34 · Low
Exploitability 0/34 · Minimal
Exposure 5/34 · Minimal