📦 Whale

by Navercorp

🔍 What is Whale?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-69234

CRITICAL CVSS 9.1 Dec 30, 2025

This vulnerability in Whale browser allows attackers to escape iframe sandbox restrictions in sidebar environments, potentially executing malicious code in the parent context. It affects all users run...

CVE-2025-62583

CRITICAL CVSS 9.8 Oct 16, 2025

This vulnerability in Whale Browser allows attackers to escape iframe sandbox restrictions in dual-tab environments, potentially enabling cross-origin attacks. It affects all users running vulnerable ...

CVE-2025-53599

CRITICAL CVSS 9.8 Jul 4, 2025

This vulnerability allows attackers to execute malicious JavaScript code in Whale browser for iOS by exploiting a flaw in how the browser handles crafted JavaScript schemes. Users running vulnerable v...

CVE-2022-24074

CRITICAL CVSS 9.8 Mar 17, 2022

CVE-2022-24074 is a critical vulnerability in Whale Browser's default Whale Bridge extension that allows compromised rendering processes to send arbitrary messages and gain control of the extension. T...

CVE-2025-69235

HIGH CVSS 7.5 Dec 30, 2025

This vulnerability allows attackers to bypass the Same-Origin Policy in Whale browser's sidebar environment, potentially enabling cross-origin data theft or manipulation. Users running Whale browser v...

CVE-2025-62585

HIGH CVSS 7.5 Oct 16, 2025

This vulnerability allows attackers to bypass Content Security Policy (CSP) protections in Whale browser by exploiting a specific scheme in dual-tab environments. Attackers could execute malicious scr...

CVE-2022-24073

HIGH CVSS 7.1 Mar 17, 2022

A vulnerability in Whale browser's Web Request API allowed malicious extensions to block access to the extension store or redirect users to arbitrary URLs when attempting to visit the store. This affe...