Bugzilla – Bug 1227687
VUL-0: CVE-2024-38526: TRACKERBUG: Polyfill Supply Chain Attack
Last modified: 2024-07-12 09:04:21 UTC
The polyfill.js is a popular open source library to support older browsers. 100K+ sites embed it using the cdn.polyfill.io domain. Notable users are JSTOR, Intuit and World Economic Forum. However, in February this year, a Chinese company bought the domain and the Github account. Since then, this domain was caught injecting malware on mobile devices via any site that embeds cdn.polyfill.io. References: https://sansec.io/research/polyfill-supply-chain-attack https://nvd.nist.gov/vuln/detail/CVE-2024-38526