Skip to content
The Cyber Security Place

Network Security

“Major Flaw” Discovered in Evernote’s Chrome Extension

Reported by infosecurity-magazine.com

A major flaw has been discovered in the code of the Web Clipper Chrome extension of note-taking service Evernote. The flaw, a universal XSS marked CVE-2019-12592 which could have allowed threat actors to extract personal information from the browser environment, was unearthed by security company Guardio and disclosed to Evernote in late May. Within a week, Evernote addressed the issue and rolled-out a complete fix.

Read the full article at infosecurity-magazine.com