Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.
References
Link Resource
https://cve.naver.com/detail/cve-2022-24074 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: naver

Published: 2022-03-17T05:20:16

Updated: 2022-03-17T05:20:16

Reserved: 2022-01-27T00:00:00


Link: CVE-2022-24074

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-17T06:15:06.887

Modified: 2023-06-30T18:50:39.697


Link: CVE-2022-24074

JSON object: View

cve-icon Redhat Information

No data.

CWE