Sceawere

Vulnerability Detail

CVE-2026-19992UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DualSafe Password Manager Information Disclosure

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
3h ago
Vendor
Orange View Limited
Product
DualSafe Password Manager & Digital Vault Extension
Attack Type
Information Disclosure
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-08-17T06:17:39.770Z",
  "pubdate": "2026-08-17T06:17:39.770Z",
  "executiveSummary": "A vulnerability has been identified in the Orange View Limited DualSafe Password Manager & Digital Vault Extension for Chrome, affecting versions up to 1.4.35. The flaw resides within an unknown function of the postMessage-based Bridge component, enabling a remote attacker to execute a manipulation that leads to unauthorized information disclosure. This security issue presents risk implications regarding the confidentiality of sensitive data stored or processed within the browser extension. The attack can be launched remotely, though it is associated with a high level of complexity and the exploitability is categorized as difficult. Despite these barriers, an exploit has been publicly released and may be actively utilized in the wild. The vendor was contacted early regarding the disclosure of this security flaw.",
  "technicalDetails": "The vulnerability exists within the postMessage-based Bridge component of the Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. The root cause stems from insecure handling or inadequate validation of cross-origin messages received via the HTML5 window.postMessage API within the extension's internal communication architecture. In browser extension environments, the postMessage mechanism is frequently utilized to facilitate inter-context communication between web pages, content scripts, and background pages or extension components.\nWhen a malicious web page or an attacker-controlled remote origin interacts with the extension, it can transmit crafted postMessage payloads to the vulnerable bridge interface. Due to insufficient origin verification or improper message sanitization, the vulnerable function processes these arbitrary or malformed messages without properly validating the sender's security context. This flaw allows malicious scripts executing in the context of a web page to interact improperly with the extension's internal APIs.\nThe attack flow proceeds as follows: First, a remote attacker lures a victim to an attacker-controlled website or leverages an existing cross-site scripting vector on a trusted site. Second, the malicious script executing in the browser initiates a communication channel with the DualSafe Password Manager extension by invoking window.postMessage targeting the extension or its accessible frame interfaces. Third, the unvalidated postMessage-based Bridge component processes the incoming message, leading to the unintended exposure or leakage of sensitive data handled by the extension. The post-exploitation impact centers primarily on information disclosure, where confidential data accessible to the password manager or digital vault component is exfiltrated to the remote adversary. The attack requires remote network exposure via the browser, operates without prior authentication or privilege requirements from the attacker's perspective, but is constrained by a high complexity level and difficult exploitability metrics."
}
CVE-2026-19992: DualSafe Password Manager Information Disclosure (LOW Severity, CVSS: 3.1) - Sceawere