


The attack would then load iFrame tags targeting specific services, hijacking Evernote to inject payloads into all iFrames: Identified as CVE-2019-12592, it is a Universal Cross-Site Scripting (UXSS) flaw caused by a “logical coding error” that breaks the browser’s domain isolation protection.įrom the description offered, exploiting it would require several steps, the first of which would be luring the user to a malicious or compromised website. Users of Evernote’s Web Clipper extension for Google Chrome should check it has been updated to the latest version after a security company published details of a dangerous security flaw.ĭiscovered by Guardio in May, ‘dangerous’ in this context means that anyone using it in its unpatched state is at risk not only of a compromise of their Evernote account but, potentially, of third-party accounts (email, social media, banking) they have open at the same time.
