Junglewise Threat Intelligence

CVE-2026-19992: Orange View Limited DualSafe Password Manager credential disclosure via postMessage bridge

CVE-2026-19992 · Severity: low · CVSS 3.1 · Published 2026-08-17

Executive brief

DualSafe Password Manager is a Chrome extension that securely stores usernames, passwords, and two-factor authentication codes. A flaw in how the extension communicates with web pages allows any script running on a website to steal stored credentials and authentication codes without validation. An attacker could exploit this through a malicious website or advertisement to compromise user accounts for services where the password manager stores both the password and two-factor secret.

Technical details

The vulnerability is a missing origin validation flaw in the extension's postMessage-based bridge (CWE-346). The content script implements a message handler that accepts credential and TOTP code retrieval requests from page-level scripts without validating the event.origin, and responds using postMessage with an unrestricted target origin ("*"). Any script running in the page context—including injected code, malicious ads, or XSS payloads—can register itself and request sensitive vault data. Exploitation requires the extension to be installed, the vault to be unlocked, and the user to visit or interact with an attacker-controlled page. The vendor has confirmed the vulnerability and committed to a fix in an upcoming update. The exploit has been published and proof-of-concept code is available.

Affected products

  • Orange View Limited DualSafe Password Manager & Digital Vault up to 1.4.35

Timeline

  • 2026-08-17: disclosed: Advisory published
  • 2026: other: Vendor contacted early; fix planned for future release

References