CVE-2022-24072: Medium severity naver whale browser vulnerability
Published Mar 17, 2022
·Updated
The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.
Affected Software
1 affected component
Navercorp Whale<3.12.129.18
Event History
Mar 17, 2022
CVE Published
via MITRE·05:20 AM
Data Sourced
via MITRE·05:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-24072?
CVE-2022-24072 has a medium severity rating due to its potential to allow arbitrary JavaScript injection.
2
How do I fix CVE-2022-24072?
To fix CVE-2022-24072, update the Whale browser to version 3.12.129.18 or later.
3
What impact does CVE-2022-24072 have on users?
CVE-2022-24072 may allow malicious extensions to manipulate the user’s browsing experience by injecting harmful scripts.
4
Which versions of Whale browser are affected by CVE-2022-24072?
Whale browser versions prior to 3.12.129.18 are affected by CVE-2022-24072.
5
Who is the vendor for CVE-2022-24072?
The vendor for CVE-2022-24072 is Navercorp, the creator of the Whale browser.