CVE Database
/

CVE-2022-24072

Back to search

CVE-2022-24072

Published: Mar 17, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.

VendorProductVersions

NAVER

NAVER Whale browser

affected
unspecified - < 3.12.129.46

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now