Junglewise Threat Intelligence

CVE-2026-8881: Securly Chrome Extension weak key derivation in AES encryption

CVE-2026-8881 · Severity: info · CVSS 0 · Published 2026-06-03

Executive brief

The Securly Chrome Extension, used by schools to filter internet content and monitor student activity, uses outdated and weak encryption methods to protect its data. Because the encryption relies on an obsolete mathematical formula and lacks proper complexity, an attacker could potentially decrypt and read sensitive configuration files or filtering rules. This could lead to the exposure of student monitoring data or allow someone to bypass the safety filters intended to protect children.

Technical details

The Securly Chrome Extension (version 3.0.7) utilizes the OpenSSL function EVP_BytesToKey with the MD5 hashing algorithm and a single iteration for AES key derivation. MD5 is cryptographically broken and susceptible to collision attacks, while a single iteration provides no effective key stretching, significantly lowering the work factor for brute-force or dictionary attacks. This vulnerability allows an attacker who has intercepted or obtained encrypted configuration files or crisis alert data to perform efficient offline cracking to recover the plaintext. This issue is part of a broader set of cryptographic weaknesses in the extension, including hardcoded keys and unencrypted HTTP transmissions. As of the advisory date, the vendor has not provided a patch.

Affected products

  • Securly Securly Chrome Extension 3.0.7

Timeline

  • 2026-03-30: other: Vendor notified
  • 2026-06-03: disclosed: Public disclosure by CERT/CC

References