CVE-2022-24072

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/03/2022
Last modified:
23/03/2022

Description

The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:navercorp:whale:*:*:*:*:*:*:*:* 3.12.129.18 (excluding)


References to Advisories, Solutions, and Tools