Guardio Labs discovered a vulnerability in Microsoft Edge's marketing API that allowed covert installation of browser extensions with broad permissions. The issue was promptly disclosed to Microsoft and resolved in February 2024. The vulnerability was due to a private API accessible from select Microsoft websites that allowed
Table of contents
“CVE-2024-21388”- Microsoft Edge’s Marketing API Exploited for Covert Extension InstallationSecuring the Browser-Extension InterfaceChromium’s Customization InfraDiving Into The EdgeThe Hidden API that Sneaks in an ExtensionExploitation by Injecting JavaScript SnippetsExploit POC — Simple, Yet Powerful ExtensionAdversaries Persistancy and Other ConsequencesDisclosure Timeline and Current StateSort: