CVE-2024-28120

CVSS V2 None CVSS V3 None
Description
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check the sender when receiving an external message. This allows an attacker to host a website that will steal the user's Codeium api-key, and thus impersonate the user on the backend autocomplete server. This issue has not been addressed. Users are advised to monitor the usage of their API key.
Overview
  • CVE ID
  • CVE-2024-28120
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-11T21:14:22.675Z
  • Last Modified Date
  • 2024-06-04T18:04:00.650Z
History
Created Old Value New Value Data Type Notes
2024-06-26 07:37:46 Added to TrackCVE