EIP-2026-104269

PRE-CVE

Google Invisible RECAPTCHA 3 - Spoof Bypass

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104269. PoCs published by Matamorphosis.

AI-analyzed exploit summary This exploit demonstrates a bypass for Google's Invisible reCAPTCHA v3 by spoofing a web app that leverages the same reCAPTCHA using the victim's site key. It automates form submission with a valid CAPTCHA token, effectively bypassing the CAPTCHA protection.

Description

Google Invisible RECAPTCHA 3 - Spoof Bypass

Exploits (1)

exploitdb WORKING POC
by Matamorphosis · textwebappsmultiple
https://www.exploit-db.com/exploits/48027

This exploit demonstrates a bypass for Google's Invisible reCAPTCHA v3 by spoofing a web app that leverages the same reCAPTCHA using the victim's site key. It automates form submission with a valid CAPTCHA token, effectively bypassing the CAPTCHA protection.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Google Invisible reCAPTCHA v3
No auth needed
Prerequisites: Site key from target web application · Firefox and GeckoDriver installed · Python 3 and required libraries
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026