Junglewise Threat Intelligence

CVE-2026-53765: ChromeDevTools chrome-devtools-mcp symlink following in PID file creation

CVE-2026-53765 · Severity: medium · CVSS 6.1 · Published 2026-06-24

Vendors: Google, npm.

Executive brief

Chrome DevTools MCP is a system component that developers use to integrate dev tools with coding agents. A local attacker on the same computer can trick the daemon into overwriting important user files (like SSH keys or shell configuration) by planting a symlink before the victim starts the daemon. This could lock a user out of their system or break critical functionality. The attack requires local access and no special privileges.

Technical details

The vulnerability is a classic symlink-follow flaw (CWE-59) in the PID file write logic. The daemon calls fs.writeFileSync() to write its process ID to /tmp/chrome-devtools-mcp-<uid>/daemon.pid without the O_NOFOLLOW flag. A local attacker can pre-create this directory and place a symlink at daemon.pid pointing to any file the victim owns (e.g., ~/.ssh/authorized_keys, ~/.bashrc). When the victim starts daemon mode, fs.writeFileSync() follows the symlink and truncates the target file to contain only the daemon's PID string. The attack requires: (1) local user account on the host, (2) target system using /tmp as runtime directory (typical on macOS or Linux without XDG_RUNTIME_DIR set), and (3) victim running the chrome-devtools daemon. The fix involves opening the PID file with O_NOFOLLOW and validating runtime directory ownership/permissions. Patch version 1.1.0 addresses this.

Affected products

  • ChromeDevTools chrome-devtools-mcp >=0.20.0, <=1.0.1

Timeline

  • 2026-06-17: disclosed: Published via GitHub advisory GHSA-3pvj-jv98-qhjq
  • 2026-06-17: patched: Patch released in version 1.1.0

References

Related threats