Junglewise Threat Intelligence

CVE-2026-8889: Securly Chrome Extension deprecated SHA-1 hashing in URL matching

CVE-2026-8889 · Severity: info · CVSS 0 · Published 2026-06-03

Executive brief

The Securly Chrome Extension, used by schools to filter internet content for students, uses an outdated and weak security method (SHA-1) to identify blocked websites. This weakness could allow a technically skilled individual to bypass content filters or predict which sites are being monitored. This may result in students accessing restricted content or the failure of safety protocols designed to protect minors online.

Technical details

The Securly Chrome Extension (v3.0.7) utilizes the deprecated SHA-1 hashing algorithm to perform URL matching for IWF CSAM (25,020 hashes) and CIPA blocklists (12,352 hashes). SHA-1 is considered cryptographically broken and susceptible to collision attacks. In this context, the use of weak cryptographic primitives allows for the potential reconstruction or manipulation of the extension's filtering logic. An attacker, particularly one on the same network, could leverage this weakness alongside other reported vulnerabilities in the extension to intercept or decrypt filtering data, potentially leading to filter bypass or unauthorized access to restricted content. At the time of advisory publication, the vendor had not provided a patch.

Affected products

  • Securly Securly Chrome Extension 3.0.7

Timeline

  • 2026-03-30: other: Vendor notified
  • 2026-06-03: disclosed: Vulnerability disclosed by CERT/CC
  • 2026-06-03: advisory: NVD published CVE-2026-8889

References