A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-8879

CVE-2026-8879: Securly Chrome Extension DoS Vulnerability

CVE-2026-8879 is a denial-of-service vulnerability in Securly Chrome Extension version 3.0.7 that hides page content indefinitely when servers are unreachable. This article covers technical details, affected versions, and mitigation.

Published: June 4, 2026

CVE-2026-8879 Overview

CVE-2026-8879 affects version 3.0.7 of the Securly Chrome Extension. The extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContentScripts() at runtime. Because this script is not declared in manifest.json, it bypasses Chrome Web Store static security review. The script runs on all URLs, immediately hides page content, creates a full-page overlay, and pauses all videos. Content is restored only when the service worker confirms the page passes filtering. If Securly's servers are unreachable, pages remain indefinitely hidden, creating a denial-of-service condition on user browsing activity.

Critical Impact

Server unreachability causes indefinite content hiding across all websites, and runtime script injection circumvents Chrome Web Store review controls.

Affected Products

  • Securly Chrome Extension version 3.0.7

Discovery Timeline

  • 2026-06-03 - CVE-2026-8879 published to NVD
  • 2026-06-03 - Last updated in NVD database

Technical Details for CVE-2026-8879

Vulnerability Analysis

The Securly Chrome Extension uses the chrome.scripting.registerContentScripts() API to register content13.min.js dynamically after installation. Content scripts declared in this manner are not subject to the static review process that examines manifest.json declarations during Chrome Web Store submission. The script targets all URLs without restriction.

Upon page load, the script applies CSS or DOM manipulation to hide all page content, injects a full-page overlay, and pauses video elements. The extension's service worker then evaluates the page against filtering rules hosted on Securly infrastructure. When the service worker returns an approval signal, the overlay is removed and content becomes visible.

The design assumes continuous connectivity to Securly's filtering servers. When those servers are unreachable, the approval signal never arrives, and the page remains hidden indefinitely. The combination of broad URL matching and a fail-closed default produces a denial-of-service condition tied to backend availability.

Root Cause

The root cause is the combination of two design choices. First, content script registration is deferred to runtime, bypassing static manifest review. Second, the page-visibility state defaults to hidden and depends on a positive remote response to transition to visible. There is no local fallback or timeout to restore content when the remote service is degraded.

Attack Vector

The attack vector is not a traditional adversarial exploit. Any disruption to Securly server reachability — outage, network filtering, DNS failure, or man-in-the-middle interference — triggers the impact. An attacker positioned to block traffic to Securly's filtering endpoints can render the user's browser unable to display any page. Refer to the CERT Vulnerability Advisory #595768 for additional technical context.

Detection Methods for CVE-2026-8879

Indicators of Compromise

  • Presence of content13.min.js registered via chrome.scripting.registerContentScripts() rather than declared in manifest.json
  • Persistent full-page overlays on all browser tabs after extension activation
  • Service worker network requests to Securly filtering endpoints failing or timing out

Detection Strategies

  • Enumerate installed Chrome extensions and inspect manifest contents against runtime-registered scripts using the chrome.scripting.getRegisteredContentScripts() API
  • Compare declared content scripts in manifest.json against the live registration set to identify scripts injected outside static review
  • Monitor browser telemetry for sustained DOM overlays and paused media elements across multiple unrelated domains

Monitoring Recommendations

  • Audit endpoints for the Securly extension at version 3.0.7 and track update status
  • Log outbound connectivity to Securly's filtering domains and alert on prolonged failures
  • Review enterprise extension management policies to flag extensions that register scripts at runtime

How to Mitigate CVE-2026-8879

Immediate Actions Required

  • Inventory affected endpoints running Securly Chrome Extension 3.0.7
  • Ensure network paths to Securly's filtering service remain reachable to avoid the fail-closed condition
  • Coordinate with Securly support for a patched extension version that addresses runtime script registration and fail-closed behavior

Patch Information

No vendor patch information is published in the available CVE data. Consult the CERT Vulnerability Advisory #595768 for vendor status updates.

Workarounds

  • Remove or disable the Securly Chrome Extension version 3.0.7 where the filtering dependency is not required
  • Use Chrome enterprise policy ExtensionInstallBlocklist to control deployment until a fixed version is released
  • Validate that DNS resolution and outbound HTTPS to Securly endpoints succeed before deploying the extension at scale

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechSecurly Chrome Extension

  • SeverityNONE

  • CVSS ScoreN/A

  • Known ExploitedNo
  • Impact Assessment
  • ConfidentialityNone
  • IntegrityNone
  • AvailabilityNone
  • Technical References
  • CERT Vulnerability Advisory #595768
  • Related CVEs
  • CVE-2026-8888: Securly Chrome Extension DoS Vulnerability

  • CVE-2026-8889: Securly Chrome Extension Vulnerability

  • CVE-2026-8881: Securly Chrome Extension Weak Crypto Flaw

  • CVE-2026-8878: Securly Chrome Extension Info Disclosure
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English