Steipete Summarize Chrome Extension Hover Summary Vulnerability Allowing Unauthorized Daemon Requests

Vulnerability

A vulnerability exists in the Steipete Summarize Chrome extension, specifically in versions prior to 0.15.1. The issue arises within the hover summary feature, where malicious pages can send synthetic mouseover events over links controlled by the attacker. This manipulation causes the extension to make authenticated requests to a daemon using stored tokens, without properly verifying the trustworthiness of the events. As a result, attackers could route these requests through the daemon to access sensitive internal endpoints, potentially exposing confidential information, especially if the targeted URLs are local or within a private network.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive internal endpoints via server-side request forgery, using authenticated tokens to route requests through the user's daemon.

Reproduction

To reproduce this vulnerability, a malicious webpage must be created that can dispatch synthetic mouseover events. This can be done by placing local or private-network URLs behind hoverable links. When a user interacts with these links, the extension will inadvertently make authenticated requests to the daemon, using stored tokens, and potentially access sensitive internal endpoints.

Remediation

Users can update to Steipete Summarize version 0.15.2 or later, where this vulnerability has been addressed.

Added: May 18, 2026, 8:24 PM
Updated: May 18, 2026, 8:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
8.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.