Security Advisory

CVE-2022-24072

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-03-17 05:20:13
Last updated 2024-08-03 03:59:23
Assigner naver
State PUBLISHED

Description

The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.