Security experts raise alarm over serious vulnerability in Evernote leading to leakage of sensitive user data

Buzz

Frequently Asked Questions

1.

What is the critical flaw discovered in the Evernote Web Clipper Chrome extension?

The critical flaw is known as Universal Cross-site Scripting (UXSS), identified as CVE-2019-12592. It allows malicious attackers to access sensitive user information from third-party services due to flawed logic encryption.
2.

How does the UXSS vulnerability affect users of Evernote Web Clipper?

The UXSS vulnerability impacts users by enabling attackers to steal cookies, personal information, login credentials, and more, by injecting malicious payloads into iframes on third-party websites visited by users.
3.

What steps has Evernote taken to address the UXSS vulnerability?

Evernote promptly released a comprehensive patch for the UXSS vulnerability on June 4th, shortly after Guardio reported the issue. Users are urged to update their Web Clipper extension to version 7.11.1.
4.

What should users do to ensure their safety regarding the Evernote Web Clipper vulnerability?

Users should immediately check if they have updated to version 7.11.1 of the Evernote Web Clipper extension and apply the patch to secure their sensitive information from potential attacks.

Mytour's content is for customer care and travel encouragement only, and we are not responsible.

For errors or inappropriate content, please contact us at: [email protected]