MEDIUMVulnerability

CVE-2026-82809

A security flaw has been discovered in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. The affected element is the function window.addEventListener of the component postMessage Handler. Performing a manipulation of the argument vidiqEvent results in information disclosure. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor explains: "At this time, vidIQ does not accept security vulnerability submissions, and we do not have a bug bounty program in place."

Properties

severity
MEDIUM
score
4.3
epss_score
0.00259
cve_id
CVE-2026-82809
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
published_at
2026-08-31T17:17:47.150
last_modified
2026-09-01T20:48:22.513
epss_percentile
0.17452

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Improper Access Control
[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82809 — Ninja Signal Threat Intelligence | Ninja Signal