Junglewise Threat Intelligence

CVE-2026-54565: rhwp browser extension service worker message validation bypass

CVE-2026-54565 · Severity: medium · CVSS 4.7 · Published 2026-09-17

Executive brief

rhwp is a document viewer and editor for HWP (Korean word processor) files that runs in web browsers as a Chrome and Firefox extension. The extension did not properly validate requests from web pages before performing sensitive network operations, allowing an attacker to trick the extension into fetching internal network resources or revealing document thumbnails to malicious websites. An attacker could exploit this by hosting a malicious web page that users visit while the extension is enabled.

Technical details

The vulnerability exists in the browser extension's service worker message handlers (`message-router.js` and `thumbnail-extractor.js`) which lacked validation of message sender origin, URL schemes, and destination addresses before issuing privileged fetch requests. An untrusted web page can send messages to the extension handlers via postMessage, causing them to fetch from localhost, private IP ranges, or link-local addresses, and return extracted preview images as data URIs readable by page-side JavaScript. The flaw also enables port scanning, internal resource enumeration, and extension fingerprinting. Attack requires user visitation of an attacker-controlled page with the extension active, and preview disclosure is limited to extractable PrvImage data. Patches in rhwp 0.7.15 and extension version 0.2.4 add sender validation, URL scheme/destination filtering, and prevent thumbnail data from being exposed directly to page DOM.

Affected products

  • rhwp rhwp before 0.7.15
  • rhwp rhwp Chrome extension before 0.2.4
  • rhwp rhwp Firefox extension before 0.2.4

Timeline

  • 2026-09-17: disclosed: CVE-2026-54565 published on NVD
  • 2026-06-06: patched: Fixed in rhwp 0.7.15 and extension version 0.2.4

References