Codeium Chrome Extension Vulnerability: Attacker Can Steal API Key and Impersonate User
CVE-2024-28120
7.5HIGH
What is CVE-2024-28120?
The codeium-chrome extension for Chrome is impacted by a vulnerability that arises from the service worker not properly validating the sender when accepting external messages. This oversight can be exploited by malicious actors who can host misleading websites. By doing so, they can capture the user's Codeium API key, subsequently allowing them to impersonate the user on the backend autocomplete server. This issue remains unresolved, prompting users to vigilantly monitor their API key usage to prevent unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
codeium-chrome <= 1.2.52
