T09 · Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Permissive Chrome DevTools Protocol Configuration Exposes Authenticated Browser Sessions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16–33
Vulnerability Type: Unsafe browser debugging configuration
Risk Level: HighVulnerable Code
bash ### Linux google-chrome \ --remote-debugging-port=9222 \ --remote-allow-origins=* \ --user-data-dir=~/.config/chrome-cdp ### macOS /Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome \ --remote-debugging-port=9222 \ --remote-allow-origins=* \ --user-data-dir="$HOME/.config/chrome-cdp"text Note: Use a dedicated `--user-data-dir` (e.g. `~/.config/chrome-cdp`) — Chrome 126+ blocks CDP on the default profile by design. Log in with your Google account once to enable sync. Note: On macOS, omit `--user-data-dir` only if you don't need sync — it gives you your real profile with extensions and custom shortcuts.The permissive
--remote-allow-origins=*configuration is repeated atSKILL.md:77-78, whileSKILL.md:172-176reiterates that the wildcard should be used and suggests exposing the real profile.Technical Analysis
Chrome DevTools Protocol provides extensive control over the browser, including navigating tabs, executing JavaScript, reading page content, inspecting network traffic, and interacting with authenticated applications. Allowing every WebSocket origin removes an important origin restriction from the CDP endpoint.
The exposure is made more severe by instructions to sign into a Google account in the debugging profile and by the alternative recommendation to expose the user's real Chrome profile. A CDP endpoint attached to either profile may provide access to authenticated pages, browser state, application tokens available to page contexts, and sensitive information displayed or transmitted by open tabs.
Although the documented Chrome command does not explicitly bind CDP to a non-loopback interface, local malicious processes and potentially hostile browser origins able to reach the ...[truncated 1791 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
--remote-allow-origins=*and configure the narrowest possible trusted origin. - Explicitly bind the debugging endpoint to loopback using an appropriate Chrome debugging address option.
- Never expose the CDP port directly to a LAN, public interface, container bridge, or untrusted proxy.
- Use a dedicated, disposable browser profile containing no personal accounts, saved credentials, payment data, or synchronized browser state.
- Remove the recommendation to sign into a Google account or use the real Chrome profile.
- Protect remote access through authenticated SSH forwarding and restrictive SSH authorization policies.
- Prefer local-only forwarding, such as
-L 127.0.0.1:9223:127.0.0.1:9222, and prohibit remote gateway binding. - Run the browser under a dedicated low-privilege operating-system account when handling untrusted sites.
- Add an explicit warning that CDP access is effectively equivalent to control of the attached browser session.
- Verify at startup that the debugging port is not reachable from non-loopback interfaces.
- Remove
