Collected research
CVE-2024-21388: Microsoft Edge's Marketing API Exploited for Covert Extension Installation
Abuses an origin-scoped Microsoft Edge marketing API that could silently install store extensions when called from trusted Microsoft sites. Script execution on an allowed origin therefore became a covert extension-installation and privilege-escalation path.
Record
- Researcher
- Oleg Zaytsev
- Format
- Advisory
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Oleg Zaytsev, first published at the original source. Preserved copies are kept so the citation survives its host.