Guardio Labs discovered a vulnerability in Microsoft Edge's marketing API that allowed covert installation of browser extensions with broad permissions. The issue was promptly disclosed to Microsoft and resolved in February 2024. The vulnerability was due to a private API accessible from select Microsoft websites that allowed the installation of extensions without user consent. The exploitation of this vulnerability could lead to the installation of malicious extensions and potential monetary gain for attackers.
Table of contents
“CVE-2024-21388”- Microsoft Edge’s Marketing API Exploited for Covert Extension InstallationSecuring the Browser-Extension InterfaceChromium’s Customization InfraDiving Into The EdgeThe Hidden API that Sneaks in an ExtensionExploitation by Injecting JavaScript SnippetsExploit POC — Simple, Yet Powerful ExtensionAdversaries Persistancy and Other ConsequencesDisclosure Timeline and Current StateSort: