The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: naver

Published: 2022-03-17T05:20:13

Updated: 2024-08-03T03:59:23.580Z

Reserved: 2022-01-27T00:00:00

Link: CVE-2022-24072

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-03-17T06:15:06.627

Modified: 2022-03-23T18:22:10.737

Link: CVE-2022-24072

cve-icon Redhat

No data.