CVE-2022-24075

CVE-2022-24075

Vendor Naver
Product NAVER Whale browser
Weakness CWE-552 · Files accessible externally
Published March 17, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.

Key dates

02Disclosure timeline

March 17, 2022 CVE published
August 3, 2024 Record updated