Home/Product/navercorp whale
Product

navercorp whale

19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-69235
< 4.35.351.12
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
7.5HIGH
CVE-2025-69234
< 4.35.351.12
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
9.1CRITICAL
CVE-2025-62585
< 4.33.325.17
Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab envi
7.5HIGH
CVE-2025-62584
< 4.33.325.17
Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.
7.5HIGH
CVE-2025-62583
< 4.33.325.17
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
9.8CRITICAL
CVE-2025-53600
< 4.32.315.22
Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment.
7.5HIGH
CVE-2025-53599
< 3.9.1.4206
Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript sch
9.8CRITICAL
CVE-2020-9754
< 1.10.6.2
NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.
5.3MEDIUM
CVE-2022-24075
< 3.12.129.18
Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to lo
6.5MEDIUM
CVE-2022-24074
< 3.12.129.18
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content
9.8CRITICAL
CVE-2022-24073
< 3.12.129.18
The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any URL when
7.1HIGH
CVE-2022-24072
< 3.12.129.18
The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extensio
6.1MEDIUM
CVE-2022-24071
< 1.14.0
A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to
4.3MEDIUM
CVE-2021-33593
< 1.14.0
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar
5.3MEDIUM
CVE-2018-12449
<= 0.4.3.0
The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.
7.8HIGH
CVE-2018-12448
< 1.3.48.4
Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visitin
5.3MEDIUM
CVE-2018-7635
< 1.0.41.8
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visitin
5.3MEDIUM
CVE-2018-9859
< 1.0.40.7
The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privil
8.1HIGH
CVE-2017-15913
all versions
The Installer in Whale allows DLL hijacking.
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin