๐Ÿ” CVE Alert

CVE-2026-19992

LOW 3.1

Orange View Limited DualSafe Password Manager & Digital Vault Extension postMessage-based Bridge information disclosure

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure.

CWE CWE-200 CWE-284
Vendor orange view limited
Product dualsafe password manager & digital vault extension
Published Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for orange view limited dualsafe password manager & digital vault extension

Be the first to know when new low vulnerabilities affecting orange view limited dualsafe password manager & digital vault extension are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Orange View Limited / DualSafe Password Manager & Digital Vault Extension
1.4.0 1.4.1 1.4.2 1.4.3 1.4.4 1.4.5 1.4.6 1.4.7 1.4.8 1.4.9 1.4.10 1.4.11 1.4.12 1.4.13 1.4.14 1.4.15 1.4.16 1.4.17 1.4.18 1.4.19 1.4.20 1.4.21 1.4.22 1.4.23 1.4.24 1.4.25 1.4.26 1.4.27 1.4.28 1.4.29 1.4.30 1.4.31 1.4.32 1.4.33 1.4.34 1.4.35

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/391193 vuldb.com: https://vuldb.com/vuln/391193/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19992 vuldb.com: https://vuldb.com/submit/873941 github.com: https://github.com/xryj920/chrome_extensions/blob/main/Orange%20View%20Limited%20DualSafe%20Password%20Manager%20%26%20Digital%20Vault%201.4.35%20exposes%20stored%20credentials%20and%20TOTP%20codes%20through%20an%20unauthenticated%20postMessage%20bridge

Credits

๐Ÿ” DRXYJ (VulDB User) VulDB CNA Team