The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-28985 The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: naver

Published:

Updated: 2024-08-03T03:59:23.580Z

Reserved: 2022-01-27T00:00:00

Link: CVE-2022-24072

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-17T06:15:06.627

Modified: 2024-11-21T06:49:46.170

Link: CVE-2022-24072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.