CRITICAL🇵🇱 Wersja polska

CVE-2025-53599

CVSS 9.8v3.1pub. 2025-07-04upd. 2025-10-01

Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.

🤖 AI Analysis
How it works

An attacker delivers to the victim a specially crafted URL or content containing a malicious javascript scheme. Whale Browser for iOS improperly validates or processes such a scheme, allowing execution of arbitrary JavaScript code in the context of the browser session. The mechanism corresponds to a classic XSS (Cross-Site Scripting) vulnerability, where lack of proper input filtering enables injection and execution of malicious scripts.

Impact

An attacker can execute arbitrary JavaScript code in the context of the victim's browser, which may lead to theft of session data, credentials, and compromise of confidentiality and integrity of data processed in the browser.

Mitigation & patch

Whale Browser for iOS should be updated to version 3.9.1.4206 or later, available in the App Store. It is recommended to implement the update immediately on all iOS devices with Whale Browser installed.

Who is affected

Whale Browser for iOS in versions prior to 3.9.1.4206

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Navercorp Whale

    APP
    Navercorp
    < 3.9.1.4206
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-69234CRITICAL9.1PL ✓same product

Whale Browser — ucieczka z iframe sandbox w środowisku sidebar

CVE-2025-62583CRITICAL9.8PL ✓same product

Whale Browser: ucieczka z iframe sandbox w środowisku dual-tab

CVE-2022-24074CRITICAL9.8PL ✓same product

Podatność w rozszerzeniu Whale Bridge w przeglądarce Naver Whale

CVE-2025-69235HIGH7.5same product

Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.

CVE-2025-62584HIGH7.5same product

Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment...