Web Hack List

Collected research

CVE-2024-21388: Microsoft Edge's Marketing API Exploited for Covert Extension Installation

Abuses an origin-scoped Microsoft Edge marketing API that could silently install store extensions when called from trusted Microsoft sites. Script execution on an allowed origin therefore became a covert extension-installation and privilege-escalation path.

Record

Researcher
Oleg Zaytsev
Format
Advisory

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Oleg Zaytsev, first published at the original source. Preserved copies are kept so the citation survives its host.