Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.
An attacker delivers to the victim a specially crafted URL or content containing a malicious javascript scheme. Whale Browser for iOS improperly validates or processes such a scheme, allowing execution of arbitrary JavaScript code in the context of the browser session. The mechanism corresponds to a classic XSS (Cross-Site Scripting) vulnerability, where lack of proper input filtering enables injection and execution of malicious scripts.
An attacker can execute arbitrary JavaScript code in the context of the victim's browser, which may lead to theft of session data, credentials, and compromise of confidentiality and integrity of data processed in the browser.
Whale Browser for iOS should be updated to version 3.9.1.4206 or later, available in the App Store. It is recommended to implement the update immediately on all iOS devices with Whale Browser installed.
Whale Browser for iOS in versions prior to 3.9.1.4206
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNavercorp Whale
APPNavercorp< 3.9.1.4206
Related vulnerabilities
Whale Browser — ucieczka z iframe sandbox w środowisku sidebar
Whale Browser: ucieczka z iframe sandbox w środowisku dual-tab
Podatność w rozszerzeniu Whale Bridge w przeglądarce Naver Whale
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment...