The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.
References
Link Resource
https://cve.naver.com/detail/cve-2022-24072 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: naver

Published: 2022-03-17T05:20:13

Updated: 2022-03-17T05:20:13

Reserved: 2022-01-27T00:00:00


Link: CVE-2022-24072

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-17T06:15:06.627

Modified: 2022-03-23T18:22:10.737


Link: CVE-2022-24072

JSON object: View

cve-icon Redhat Information

No data.