Fortinet: FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs

Fortinet: FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs

Critical FortiPAM Chrome Extension Vulnerability Exposes Sensitive Data (CVE-2026-84388)

A severe vulnerability in the Fortinet FortiPAM Chrome extension (CVE-2026-84388, CVSS 9.1) has been disclosed, allowing attackers to manipulate browser proxy settings, open arbitrary tabs, and record activity within them. The flaw, reported by Am I Being Pwned, stems from a trust mechanism failure in the extension’s webRequest listener, which blindly adds requested hostnames to a trusted server list without proper validation.

The extension, designed for privileged access management, retrieves configurations from a FortiPAM server to launch sessions, inject credentials, and enforce proxy policies. However, two key weaknesses enable exploitation:

  1. Unauthenticated Session Launching – The extension’s externally_connectable setting exposes its message interface to all URLs, while its token-handling mechanism accepts non-JWT values without validation. Attackers can craft malicious requests with fabricated tokens, forcing the extension to retrieve session configurations from attacker-controlled domains.
  2. Consent Bypass – The permission dialog appears in the page’s main-world DOM, allowing malicious JavaScript to programmatically click the "Allow" button. This grants attackers full control over tab openings and screen recordings.

Once exploited, attackers can redirect proxy settings, select target tabs, and exfiltrate sensitive data including credentials, API keys, and session recordings via phishing or malicious websites. While HTTPS mitigates proxy interception, the tab-recording capability remains a direct threat to exposed information.

Fortinet issued an advisory (FG-IR-26-168) on August 1, following a report received on July 17. No confirmed in-the-wild exploitation has been observed. Organizations are advised to update affected extensions immediately and audit privileged session logs for unauthorized activity.

Source: https://gbhackers.com/fortipam-chrome-extension-vulnerability/

Fortinet cybersecurity rating report: https://www.rankiteo.com/company/fortinet

"id": "FOR1788963956",
"linkid": "fortinet",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of FortiPAM Chrome '
                                              'Extension',
                        'industry': 'Information Technology, Cybersecurity',
                        'name': 'Fortinet',
                        'type': 'Cybersecurity Company'}],
 'attack_vector': 'Malicious Chrome Extension Exploitation',
 'customer_advisories': 'Users of FortiPAM Chrome Extension should update '
                        'immediately and review session logs.',
 'data_breach': {'data_exfiltration': 'Potential (via malicious websites or '
                                      'phishing)',
                 'personally_identifiable_information': 'Potential '
                                                        '(credentials, session '
                                                        'data)',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Credentials',
                                              'API keys',
                                              'Session recordings']},
 'date_detected': '2026-07-17',
 'date_publicly_disclosed': '2026-08-01',
 'description': 'A severe vulnerability in the Fortinet FortiPAM Chrome '
                'extension (CVE-2026-84388, CVSS 9.1) has been disclosed, '
                'allowing attackers to manipulate browser proxy settings, open '
                'arbitrary tabs, and record activity within them. The flaw '
                'stems from a trust mechanism failure in the extension’s '
                'webRequest listener, which blindly adds requested hostnames '
                'to a trusted server list without proper validation. The '
                'extension retrieves configurations from a FortiPAM server to '
                'launch sessions, inject credentials, and enforce proxy '
                'policies, but two key weaknesses enable exploitation: '
                'unauthenticated session launching and consent bypass. '
                'Attackers can redirect proxy settings, select target tabs, '
                'and exfiltrate sensitive data including credentials, API '
                'keys, and session recordings via phishing or malicious '
                'websites.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'vulnerability disclosure',
            'data_compromised': 'Credentials, API keys, session recordings, '
                                'sensitive data',
            'identity_theft_risk': 'High (due to exposure of credentials and '
                                   'session data)',
            'operational_impact': 'Potential unauthorized access to privileged '
                                  'sessions',
            'systems_affected': 'FortiPAM Chrome Extension'},
 'investigation_status': 'Disclosed, no confirmed in-the-wild exploitation',
 'lessons_learned': 'Need for stricter validation in extension trust '
                    'mechanisms and permission dialogs to prevent unauthorized '
                    'access and consent bypass.',
 'post_incident_analysis': {'corrective_actions': 'Patch vulnerability, '
                                                  'enforce stricter validation '
                                                  'for extension trust '
                                                  'mechanisms, and secure '
                                                  'permission dialogs against '
                                                  'programmatic clicks.',
                            'root_causes': 'Trust mechanism failure in '
                                           'webRequest listener, '
                                           'unauthenticated session launching, '
                                           'and consent bypass in permission '
                                           'dialogs.'},
 'recommendations': 'Update affected FortiPAM Chrome extensions immediately, '
                    'audit privileged session logs for unauthorized activity, '
                    'and enforce HTTPS to mitigate proxy interception risks.',
 'references': [{'source': 'Fortinet Advisory', 'url': 'FG-IR-26-168'},
                {'source': 'Am I Being Pwned'}],
 'response': {'communication_strategy': 'Public advisory issued (FG-IR-26-168)',
              'containment_measures': 'Update affected extensions immediately',
              'enhanced_monitoring': 'Audit privileged session logs for '
                                     'unauthorized activity',
              'remediation_measures': 'Patch vulnerability (FG-IR-26-168)'},
 'stakeholder_advisories': 'Organizations advised to update affected '
                           'extensions and monitor for unauthorized activity.',
 'title': 'Critical FortiPAM Chrome Extension Vulnerability Exposes Sensitive '
          'Data (CVE-2026-84388)',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': 'CVE-2026-84388 (CVSS 9.1)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.