Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
CVE-2026-84388 is a vulnerability in the FortiPAM Chrome extension used for Privileged Access Management. It allows any website to control the browser's proxy settings for the session and to open new tabs that can be screen recorded and sent to an attacker's server. This enables trivial phishing attacks by capturing sensitive user activity in attacker-controlled tabs. The vulnerability has a high impact due to the ability to monitor user activity and manipulate proxy settings without user consent.
AI Analysis
Technical Summary
The FortiPAM Chrome extension, which has over 1 million users, contains a vulnerability (CVE-2026-84388) that permits any visited website to set the browser's proxy for the session and to open new tabs that can be screen recorded and streamed to an attacker's server. This flaw allows attackers to perform phishing attacks by viewing sensitive information in the attacker-created tabs. The vulnerability was disclosed on Reddit's r/netsec and is rated with a CVSS score of 9.1, indicating critical severity. No affected versions or patch information are provided in the source data.
Potential Impact
An attacker can manipulate the browser's proxy settings and monitor user activity by recording the content of tabs they open, enabling phishing attacks and potential data exposure. This compromises user privacy and security by allowing unauthorized control over browser behavior and capturing sensitive information without user knowledge.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling or uninstalling the FortiPAM Chrome extension to prevent exploitation. Monitor vendor channels for updates and apply patches promptly once released.
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
Description
CVE-2026-84388 is a vulnerability in the FortiPAM Chrome extension used for Privileged Access Management. It allows any website to control the browser's proxy settings for the session and to open new tabs that can be screen recorded and sent to an attacker's server. This enables trivial phishing attacks by capturing sensitive user activity in attacker-controlled tabs. The vulnerability has a high impact due to the ability to monitor user activity and manipulate proxy settings without user consent.
Reddit Discussion
TL;DR. The FortiPAM Chrome extension (1M+ users), used for Privileged Access Management, allowed any site to set the browser's proxy for the session, alongside allowing any site to create a new tab and send screen recordings of it to an attacker's server. That makes for trivial phishing attacks which only require the user to view something sensitive in the attacker-opened tab. CVSS 9.1 | CVE-2026-84388.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The FortiPAM Chrome extension, which has over 1 million users, contains a vulnerability (CVE-2026-84388) that permits any visited website to set the browser's proxy for the session and to open new tabs that can be screen recorded and streamed to an attacker's server. This flaw allows attackers to perform phishing attacks by viewing sensitive information in the attacker-created tabs. The vulnerability was disclosed on Reddit's r/netsec and is rated with a CVSS score of 9.1, indicating critical severity. No affected versions or patch information are provided in the source data.
Potential Impact
An attacker can manipulate the browser's proxy settings and monitor user activity by recording the content of tabs they open, enabling phishing attacks and potential data exposure. This compromises user privacy and security by allowing unauthorized control over browser behavior and capturing sensitive information without user knowledge.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling or uninstalling the FortiPAM Chrome extension to prevent exploitation. Monitor vendor channels for updates and apply patches promptly once released.
Technical Details
- Source Type
- Subreddit
- netsec
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6aa1415cacd9273b493ae855
Added to database: 09/09/2026, 11:22:04 UTC
Last enriched: 09/09/2026, 11:22:08 UTC
Last updated: 09/09/2026, 13:22:00 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.