Junglewise Threat Intelligence

CVE-2026-8876: Securly Chrome Extension hardcoded AES keys in securly.min.js

CVE-2026-8876 · Severity: info · Published 2026-06-03

Executive brief

The Securly Chrome Extension, used by schools to monitor and filter student internet activity, contains hardcoded security keys within its source code. These keys allow anyone with access to the extension's files to decrypt sensitive information, including crisis alert keywords and intervention site data. This could lead to the exposure of private safety monitoring configurations and student safety protocols.

Technical details

The Securly Chrome Extension (version 3.0.7) contains hardcoded, plaintext AES passphrases within the 'securly.min.js' file. These static keys are used to decrypt sensitive configuration data, including crisis alert keywords and intervention site lists. An attacker who can access the extension's source code or intercept encrypted traffic can use these keys to recover the original plaintext data. This vulnerability is compounded by other issues in the same version, such as the use of weak key derivation (EVP_BytesToKey with MD5) and unencrypted HTTP transmissions. As of the advisory date, the vendor has not provided a patch.

Affected products

  • Securly Securly Chrome Extension 3.0.7

Timeline

  • 2026-03-30: other: Vendor notified
  • 2026-06-03: disclosed: Vulnerability disclosed by CERT/CC
  • 2026-06-03: advisory

References