Whale Browser
by Naver
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-62583 | Cri | 0.64 | 9.8 | 0.00 | Oct 16, 2025 | Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment. | ||
| CVE-2025-53599 | Cri | 0.64 | 9.8 | 0.00 | Jul 4, 2025 | Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme. | ||
| CVE-2025-69234 | Cri | 0.59 | 9.1 | 0.00 | Dec 30, 2025 | Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment. | ||
| CVE-2025-69235 | Hig | 0.49 | 7.5 | 0.00 | Dec 30, 2025 | Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment. | ||
| CVE-2025-62585 | Hig | 0.49 | 7.5 | 0.00 | Oct 16, 2025 | Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment. | ||
| CVE-2025-62584 | Hig | 0.49 | 7.5 | 0.00 | Oct 16, 2025 | Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment. | ||
| CVE-2025-53600 | Hig | 0.49 | 7.5 | 0.00 | Jul 4, 2025 | Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment. | ||
| CVE-2023-25632 | Med | 0.36 | 5.5 | 0.00 | Nov 27, 2023 | The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature. |
- risk 0.64cvss 9.8epss 0.00
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
- risk 0.64cvss 9.8epss 0.00
Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.
- risk 0.59cvss 9.1epss 0.00
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
- risk 0.49cvss 7.5epss 0.00
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
- risk 0.49cvss 7.5epss 0.00
Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.
- risk 0.49cvss 7.5epss 0.00
Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.
- risk 0.49cvss 7.5epss 0.00
Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment.
- risk 0.36cvss 5.5epss 0.00
The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.