Cross-Origin Resource Vulnerability in Dark Reader Extension
CVE-2025-68467

3.4LOW

Key Information:

Vendor

Darkreader

Vendor
CVE Published:
4 March 2026

What is CVE-2025-68467?

The Dark Reader extension faced a vulnerability where cross-origin style sheets could be improperly accessed and stored, potentially exposing users to risks. Prior to the release of version 4.9.117, dynamic dark mode features allowed for unintended style sheet requests from local servers if the URL was known. Although there were no reported exploits as of December 18, 2025, the issue has been addressed in subsequent updates which restrict cross-origin requests and enhance security standards. Users are encouraged to verify they have the latest version installed to protect against potential vulnerabilities.

Affected Version(s)

darkreader < 4.9.117

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.