Blog

If You Use Evernote Your Data May Have Been Exposed

By baypointetech July 6, 2019

Do you use Evernote Web Clipper for the Chrome web browser?


If so, be advised that the developer recently reported that a critical flaw in the extension could allow hackers to access user information from third party online services.


Online security company Guardio discovered the flaw and had this to say:


"Due to Evernote's widespread popularity, this issue had the potential of affecting its consumers and companies who use the extension - about 4,600,000 users at the time of discovery."


The issue is being traced as CVE-2019-12592 and is a Universal Cross-Site Scripting (UXSS) coding error that makes it possible for an attacker to, in the words of Guardio's research team, "bypass the browser's same origin policy, granting the attacker code execution privileges in Iframes beyond Evernote's domain."



Once Chrome's Site Isolation security feature is circumvented, account data from other websites the user visits using Chrome, "including authentication, financials, private conversations in social media, personal emails, and more" are vulnerable and can be harvested with ease.


According to Guardio's CTO Michael Vainshtein:


"The vulnerability we discovered is a testament to the importance of scrutinizing browser extensions with extra care. People need to be aware that even the most trusted extensions can contain a pathway for attackers. All it takes is a single unsafe extension to compromise anything you do or store online. The ripple effect is immediate and intense."


Guardio reported the issue to Evernote on May 27th and the company moved quickly to patch the code. At this point, the only thing you need to do in order to be sure you're protected is check the version of your Evernote extension. If you're using version 7.11.1 or later, you're all set. Updating this extension should be given your highest priority. The risks of exposure are enormous.

 

Used with permission from Article Aggregator

Related Posts

By Mersad September 23, 2025
How can a small-scale establishment stand out in today's competitive market? With the shift toward digital-first experiences, mobile apps help businesses stay relevant and accessible, no matter their size. Learn more about them here.
By Mersad September 22, 2025
Many businesses across various industries have already implemented a remote work model. Around 35% of Silicon Valley workers, for example, now work from home, a sharp rise from the 2019 pre-pandemic period's 6%, and for good reason. This shift brings many worthwhile advantages, including:
By Mersad September 20, 2025
There’s no question that the traditional username and password combination is a weak link when it comes to online security. For several years, experts have encouraged businesses to implement passkeys to overcome the pitfalls of traditional passwords, which have become increasingly vulnerable to cybercriminals.
By Mersad September 19, 2025
Just how safe is your establishment from online threats? A new phishing scam is making waves and targeting US-based organizations. Learn more about it here so you can bolster your defenses.
By Mersad September 18, 2025
Are you finding it harder to keep your offerings profitable over time? By investing in innovation, establishments can predict and control physical wear, combat obsolescence, and even discover new utilization opportunities. Learn more about technology for longer product lifecycles here.

Contact Information

1035 Medina Rd, Suite #800

Medina, OH 44256