Steipete Summarize Missing Authorization Vulnerability in Chrome Extension Automation

Vulnerability

A missing authorization vulnerability has been identified in the Steipete Summarize Chrome extension, affecting versions prior to 0.15.1. This vulnerability allows attackers to execute browser automation actions without user approval for each individual action, bypassing a crucial confirmation step. Exploitation is possible when the extension's automation feature is enabled, and attackers can manipulate the agent by injecting malicious content into pages or summaries. This manipulation can trigger automation tools like navigation or debugger-related actions, all without the user's consent.

Impact

Exploitation of this vulnerability allows for unauthorized execution of browser automation tasks, which could include navigating to malicious websites or manipulating the browser environment through debugging tools.

Reproduction

To reproduce this vulnerability, use a version of the Steipete Summarize Chrome extension prior to 0.15.1. Enable the extension's automation feature. Then, interact with a page or summary that contains injected malicious content. The extension will execute automation tasks, such as navigation or debugging actions, without requesting user approval for each individual task.

Remediation

Users can update to Steipete Summarize version 0.15.2 or later, where this vulnerability has been addressed.

Added: May 18, 2026, 8:23 PM
Updated: May 18, 2026, 8:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.9
exploitability
7.4
remediation
0.0
relevance
8.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.