Information Disclosure Vulnerability in vidIQ Vision for YouTube Extension by vidIQ
CVE-2026-82809
Key Information:
- Vendor
Vidiq
- Vendor
- CVE Published:
- 31 August 2026
Badges
What is CVE-2026-82809?
An information disclosure vulnerability has been identified in the vidIQ Vision for YouTube Extension (version 3.199.0) for Chrome. The flaw resides in the window.addEventListener method utilized by the postMessage handler, allowing an attacker to manipulate the argument 'vidiqEvent' and extract sensitive information. This type of exploit can be executed remotely, posing a significant security risk. It is noteworthy that vidIQ does not currently accept submissions for security vulnerabilities nor has it established a bug bounty program.
Affected Version(s)
Vision for YouTube Extension 3.199.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
