Executive brief
The Securly Chrome Extension, used by schools to manage student internet safety and filter content, fails to encrypt certain data transmissions. This allows an attacker on the same network to view or modify filtering rules and crisis alert keywords. Such an exploit could lead to students accessing restricted content or being blocked from legitimate educational resources.
Technical details
The Securly Chrome Extension (v3.0.7) utilizes the Fetch API to download JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP. While other components of the extension use HTTPS for IWF and CIPA data, this specific endpoint lacks TLS implementation. An on-path attacker can intercept these transmissions to view sensitive filtering logic or perform a machine-in-the-middle (MitM) attack to modify the JSON payloads. This can result in the bypass of safety filters or the injection of malicious patterns. As of the advisory date, the vendor has not provided a patch.
Affected products
- Securly Chrome Extension 3.0.7
Timeline
- 2026-03-30: other: Vendor notified
- 2026-06-03: disclosed: Public disclosure by CERT/CC
- 2026-06-03: advisory: NVD publication date