CVE-2025-62583
BaseFortify
Publication date: 2025-10-16
Last updated on: 2025-10-21
Assigner: Naver Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| navercorp | whale | to 4.33.325.17 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-358 | The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Whale Browser versions before 4.33.325.17 allows an attacker to escape the iframe sandbox when using a dual-tab environment. This means that an attacker can bypass the security restrictions normally imposed on iframes, potentially gaining unauthorized access or control beyond the intended sandboxed area.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to break out of the iframe sandbox, which may lead to unauthorized access to browser content or data, potentially compromising user privacy or security within the browser environment.