Description
Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.
Problem types
CWE-358 Improperly Implemented Security Check for Standard
Product status
4.33.325.17
Credits
Mingi Jung, mingijung.grape@gmail.com, Ulsan National Institute of Science and Technology-Web Sec Lab
References
cve.naver.com/detail/cve-2025-62585.html (NAVER Security Advisory)