📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Technology/AI Services LOW 1h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 5h Global vulnerability Software and Technology HIGH 5h Global vulnerability Software and Cloud Services CRITICAL 5h Global phishing Artificial Intelligence and Email Security HIGH 6h Global phishing Email and Communications CRITICAL 7h Global vulnerability Enterprise Software / E-commerce CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 7h Global vulnerability Information Technology HIGH 8h Global general Technology/AI Services LOW 1h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 5h Global vulnerability Software and Technology HIGH 5h Global vulnerability Software and Cloud Services CRITICAL 5h Global phishing Artificial Intelligence and Email Security HIGH 6h Global phishing Email and Communications CRITICAL 7h Global vulnerability Enterprise Software / E-commerce CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 7h Global vulnerability Information Technology HIGH 8h Global general Technology/AI Services LOW 1h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 5h Global vulnerability Software and Technology HIGH 5h Global vulnerability Software and Cloud Services CRITICAL 5h Global phishing Artificial Intelligence and Email Security HIGH 6h Global phishing Email and Communications CRITICAL 7h Global vulnerability Enterprise Software / E-commerce CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 7h Global vulnerability Information Technology HIGH 8h
Vulnerabilities

CVE-2026-8889

High
CWE-407 — Weakness Type
Published: Jun 3, 2026  ·  Modified: Jun 10, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).

🤖 AI Executive Summary

Securly Chrome Extension version 3.0.7 uses cryptographically weak SHA-1 hashing for critical security functions including CSAM URL matching and CIPA compliance blocklists. This vulnerability could allow attackers to forge or manipulate hash values, potentially bypassing content filtering controls in educational and corporate environments. The absence of available patches creates immediate risk for Saudi organizations relying on this extension for compliance and security.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 8, 2026 07:16
🇸🇦 Saudi Arabia Impact Assessment
High impact for Saudi educational institutions (Ministry of Education, universities), government agencies using content filtering, and corporate environments. ARAMCO and other critical infrastructure organizations using Chrome extensions for security controls are at risk. Telecom providers (STC, Mobily) deploying this extension for network-level filtering face potential bypass scenarios. The vulnerability affects CIPA compliance mechanisms critical for Saudi organizations handling sensitive content and minors' internet access.
🏢 Affected Saudi Sectors
Education (Ministry of Education, Universities) Government (NCA, NCSC, federal agencies) Banking and Financial Services (SAMA regulated) Healthcare (MOH, private hospitals) Energy (ARAMCO, utilities) Telecommunications (STC, Mobily, Zain)
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Audit all deployments of Securly Chrome Extension 3.0.7 across your organization
2. Identify systems where this extension is active, particularly in educational and government networks
3. Document all CSAM and CIPA blocklist dependencies on this extension

Patching Guidance:
1. Contact Securly support immediately to request SHA-256 migration timeline
2. Upgrade to the latest available version when released (monitor Securly security advisories)
3. Implement version pinning controls to prevent automatic downgrades

Compensating Controls (until patch available):
1. Deploy network-level content filtering (proxy/firewall) as primary control, treating extension as secondary
2. Implement DNS filtering with DNSSEC validation using SHA-256+ algorithms
3. Enable browser policies to restrict extension permissions and disable hash-based matching features if possible
4. Deploy endpoint detection and response (EDR) to monitor for hash collision exploitation attempts
5. Implement additional CSAM detection mechanisms through third-party services with modern cryptography

Detection Rules:
1. Monitor for Securly extension processes attempting to load or validate hash tables
2. Alert on any modifications to extension files or hash database files
3. Track failed content filtering decisions that may indicate hash collisions
4. Monitor for unusual patterns in blocked/allowed content decisions
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع نشرات إضافة Securly Chrome 3.0.7 عبر مؤسستك
2. تحديد الأنظمة التي تعمل فيها هذه الإضافة، خاصة في الشبكات التعليمية والحكومية
3. توثيق جميع تبعيات CSAM و CIPA على هذه الإضافة

إرشادات التصحيح:
1. اتصل بدعم Securly فوراً لطلب جدول زمني لترحيل SHA-256
2. قم بالترقية إلى أحدث إصدار متاح عند إصداره (راقب تنبيهات أمان Securly)
3. تطبيق عناصر التحكم في تثبيت الإصدار لمنع الانحدار التلقائي

عناصر التحكم البديلة (حتى توفر التصحيح):
1. نشر تصفية المحتوى على مستوى الشبكة (وكيل/جدار حماية) كعنصر تحكم أساسي
2. تطبيق تصفية DNS مع التحقق من DNSSEC باستخدام خوارزميات SHA-256+
3. تفعيل سياسات المتصفح لتقييد أذونات الإضافة وتعطيل ميزات المطابقة القائمة على التجزئة
4. نشر كشف ومعالجة نقاط النهاية (EDR) لمراقبة محاولات استغلال تصادمات التجزئة
5. تطبيق آليات كشف CSAM إضافية من خلال خدمات الجهات الخارجية بتشفير حديث

قواعد الكشف:
1. مراقبة عمليات إضافة Securly التي تحاول تحميل أو التحقق من جداول التجزئة
2. تنبيه على أي تعديلات على ملفات الإضافة أو ملفات قاعدة بيانات التجزئة
3. تتبع قرارات تصفية المحتوى الفاشلة التي قد تشير إلى تصادمات التجزئة
4. مراقبة الأنماط غير العادية في قرارات المحتوى المحظور/المسموح
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.10.1.1 - Cryptographic controls (use of weak SHA-1) ECC 2024 A.8.2.3 - Access control to security functions ECC 2024 A.12.6.1 - Management of technical vulnerabilities
🔵 SAMA CSF
SAMA CSF ID.SC-4 - Supply chain security (third-party extension security) SAMA CSF PR.DS-1 - Data security and cryptographic measures SAMA CSF DE.CM-1 - Detection and monitoring of anomalies
🟡 ISO 27001:2022
ISO 27001:2022 A.10.1 - Cryptography (weak algorithm usage) ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.8.1.3 - Segregation of duties
🟣 PCI DSS v4.0.1
PCI DSS 3.4 - Render PAN unreadable (if extension processes payment data) PCI DSS 6.2 - Security patches and updates
📦 Affected Products / CPE 1 entries
securly:securly:3.0.7
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityN — None / Network
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-407
EPSS0.02%
Exploit No
Patch ✗ No
Published 2026-06-03
Source Feed nvd
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-407
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.