Accessibility Statement Skip Navigation
  • Back to Global Sites
  • +972-77-2005042
  • Blog
  • Journalists
  • GDPR
  • Send a Release
PR Newswire: news distribution, targeting and monitoring
  • News
  • Products
  • Contact
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • Telephone

    • +972-77-2005042 from 8 AM - 11 PM IL

    • Contact
    • Contact

      +972-77-2005042
      from 8 AM - 11 PM IL

  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR

Guardio Discovers Major Vulnerability in Evernote's Chrome Extension

The code flaw, repaired immediately upon notification, could have allowed threat actors to extract personal information from the browser environment


News provided by

Guardio LTD.

12 Jun, 2019, 17:00 IDT

Share this article

Share toX

Share this article

Share toX

TEL AVIV, Israel, June 12, 2019 /PRNewswire/ -- Guardio, a leading browser-centric and cloud security company, discovered a major flaw in Evernote's Web Clipper Chrome extension's code that left it vulnerable, potentially allowing threat actors to access personal information from users' online services.

The vulnerability, a Universal XSS marked CVE-2019-12592, was discovered as part of Guardio's ongoing security analysis efforts using a combination of internal technology and researchers. Guardio disclosed the vulnerabilities to Evernote during the last week of May, which prompted Evernote to address them and roll out a complete fix - within less than a week.

Due to Evernote's widespread popularity, this issue had the potential of affecting its consumers and companies who use the extension – about 4,600,000 users at the time of discovery.

The logical coding error in the Web Clipper extension could have allowed an attacker to bypass the browser's same origin policy, granting the attacker code execution privileges in Iframes beyond Evernote's domain. As the browser's domain-isolation mechanisms were broken, code could be executed that could allow an attacker to perform actions on behalf of the user as well as grant access to sensitive user information on affected third-party web pages and services, including authentication, financials, private conversations in social media, personal emails, and more.

According to its security page, Evernote "periodically assesses its infrastructure and applications for vulnerabilities and remediates those that could impact the security of customer data."

As the trend to move to the cloud continues, the browser is becoming the users de-facto OS - replacing where users use their applications and access their data. While app authors strive to provide faster, smoother user experiences, extensions usually have permissions to access a trove of sensitive resources, inadvertently posing a much greater security risk than traditional websites. Guardio's protection comes into play in these new potentially vulnerable threat areas.

"The vulnerability we discovered is a testament to the importance of scrutinizing browser extensions with extra care. People need to be aware that even the most trusted extensions can contain a pathway for attackers," said Michael Vainshtein, CTO, Guardio. "All it takes is a single unsafe extension to compromise anything you do or store online. The ripple effect is immediate and intense."

About Guardio

Guardio is a new breed of cyber security product designed to tackle threats and security concerns within the browser. Mitigating threats from malicious or unwanted extensions is an integral part of how Guardio protects its users, able to neutralize harmful extensions in real-time. Combined with strong anti-phishing capabilities, malicious ad blocking and information leak monitoring. Guardio bundles a complete online protection suite where it matters most - your browser.

Media Contact
Amy Kenigsberg, K2 Global Communications
http://k2-gc.com/ 
[email protected] 
Tel: +972-9-794-1681 (+2 GMT)
Mobile: +972-524-761-341
U.S.: +1-913-440-4072 (+7 ET)

SOURCE Guardio LTD.

Related Links

https://guard.io

Modal title

Contact PR Newswire

  • +972-77-2005042
    from 8 AM - 11 PM IL

Global Sites

  • APAC
  • APAC - Traditional Chinese
  • Asia
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany

 

  • India
  • Indonesia
  • Israel
  • Italy
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland

 

  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921
Global Sites
  • Asia
  • Brazil
  • Canada
  • Csezh
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Israel
  • Italie
  • Mexico
  • Middle East
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States
+972-77-2005042
from 8 AM - 11 PM IL
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • Cookie Settings
Copyright © 2025 Cision US Inc.