CRITICAL🇵🇱 Wersja polska

CVE-2025-69234

CVSS 9.1v3.1pub. 2025-12-30upd. 2026-01-13

Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.

🤖 AI Analysis
How it works

The sandbox mechanism for iframe elements should restrict the capabilities of code running inside the embedded frame, preventing it from accessing resources of the parent browser context. In the described case (CWE-358 — Improperly Implemented Security Check), the verification of sandbox restrictions in the sidebar environment is improperly implemented, which allows it to be bypassed. An attacker can construct a specially crafted website or sidebar content to escape the isolated iframe context and gain access to resources they should not have access to.

Impact

An attacker can gain unauthorized access to sensitive data and modify resources or data outside the isolated iframe context, which corresponds to high impact on confidentiality and integrity (CVSS C:H/I:H).

Mitigation & patch

The Whale browser should be updated to version 4.35.351.12 or newer. Detailed information is available at: https://cve.naver.com/detail/cve-2025-69234.html

Who is affected

Navercorp Whale Browser in all versions prior to 4.35.351.12.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Navercorp Whale

    APP
    Navercorp
    < 4.35.351.12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-62583CRITICAL9.8PL ✓same product

Whale Browser: ucieczka z iframe sandbox w środowisku dual-tab

CVE-2025-53599CRITICAL9.8PL ✓same product

XSS w Whale Browser dla iOS — wykonanie złośliwych skryptów przez schemat javascript

CVE-2022-24074CRITICAL9.8PL ✓same product

Podatność w rozszerzeniu Whale Bridge w przeglądarce Naver Whale

CVE-2025-69235HIGH7.5same product

Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.

CVE-2025-62584HIGH7.5same product

Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment...