
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
FortinetFortiPAMChrome extensionvulnerabilityCVE-2026-84388proxyphishingsecurityprivileged access managementbrowser security
The FortiPAM Chrome extension, which has over 1 million users and is used for Privileged Access Management, contained vulnerabilities that allowed any website to set the browser's proxy for the session and create new tabs while sending screen recordings to an attacker's server. This enabled trivial phishing attacks requiring only that a user view sensitive content in an attacker-opened tab. The vulnerability has been assigned CVE-2026-84388 with a CVSS score of 9.1.