Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.
References
Link | Resource |
---|---|
https://cve.naver.com/detail/cve-2022-24074 | Vendor Advisory |
Configurations
Information
Published : 2022-03-16 23:15
Updated : 2022-03-23 11:50
NVD link : CVE-2022-24074
Mitre link : CVE-2022-24074
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
navercorp
- whale