Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
The sandbox mechanism for iframe elements should restrict the capabilities of code running inside the embedded frame, preventing it from accessing resources of the parent browser context. In the described case (CWE-358 — Improperly Implemented Security Check), the verification of sandbox restrictions in the sidebar environment is improperly implemented, which allows it to be bypassed. An attacker can construct a specially crafted website or sidebar content to escape the isolated iframe context and gain access to resources they should not have access to.
An attacker can gain unauthorized access to sensitive data and modify resources or data outside the isolated iframe context, which corresponds to high impact on confidentiality and integrity (CVSS C:H/I:H).
The Whale browser should be updated to version 4.35.351.12 or newer. Detailed information is available at: https://cve.naver.com/detail/cve-2025-69234.html
Navercorp Whale Browser in all versions prior to 4.35.351.12.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NNavercorp Whale
APPNavercorp< 4.35.351.12
Related vulnerabilities
Whale Browser: ucieczka z iframe sandbox w środowisku dual-tab
XSS w Whale Browser dla iOS — wykonanie złośliwych skryptów przez schemat javascript
Podatność w rozszerzeniu Whale Bridge w przeglądarce Naver Whale
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment...