CVE-2026-19992
Received Received - Intake

Information Disclosure in DualSafe Password Manager Chrome Extension

Vulnerability report for CVE-2026-19992, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: VulDB

Description

A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
orange_view_limited dualsafe_password_manager to 1.4.35 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the DualSafe Password Manager Chrome extension up to version 1.4.35. It involves an unauthenticated postMessage bridge that allows any script on a webpage to request and receive sensitive data like stored credentials and TOTP codes without proper validation. The extension accepts messages without checking the origin, enabling malicious pages to exploit this and retrieve vault data when the extension is installed and unlocked.

Detection Guidance

Check if the DualSafe Password Manager & Digital Vault Chrome extension version 1.4.35 or earlier is installed. Inspect browser extensions for unauthenticated postMessage bridges by reviewing extension source code or using developer tools to monitor message events.

Impact Analysis

If you use the vulnerable version of DualSafe Password Manager, an attacker could trick you into visiting a malicious webpage. This page could then extract your saved usernames, passwords, and live TOTP codes, potentially leading to account takeovers. The attack requires user interaction, such as visiting the attacker's page, but no further privileges are needed.

Compliance Impact

This vulnerability could lead to unauthorized access to stored credentials and TOTP codes, which may result in data breaches. For GDPR, this could violate principles of data protection and user privacy, potentially leading to fines or legal consequences. For HIPAA, exposure of sensitive credentials could compromise protected health information security.

Mitigation Strategies

Uninstall the DualSafe Password Manager & Digital Vault Chrome extension version 1.4.35 or earlier. Monitor vendor updates for a patched version and avoid visiting untrusted websites while the vulnerable extension is installed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19992. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart