Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.
References
Link | Resource |
---|---|
https://cve.naver.com/detail/cve-2022-24074 | Vendor Advisory |
https://cve.naver.com/detail/cve-2022-24074 | Vendor Advisory |
Configurations
History
21 Nov 2024, 06:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://cve.naver.com/detail/cve-2022-24074 - Vendor Advisory |
30 Jun 2023, 18:50
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-668 |
Information
Published : 2022-03-17 06:15
Updated : 2024-11-21 06:49
NVD link : CVE-2022-24074
Mitre link : CVE-2022-24074
CVE.ORG link : CVE-2022-24074
JSON object : View
Products Affected
navercorp
- whale
CWE
CWE-668
Exposure of Resource to Wrong Sphere