CVE-2018-12448: Input Validation
Published Aug 2, 2018
·Updated
Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, which allows an attacker to display a malicious web page with a fake domain name.
Affected Software
1 affected component
Navercorp Whale<1.3.48.4
Event History
Aug 2, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-12448?
The severity of CVE-2018-12448 is considered moderate as it allows attackers to spoof URLs in the Whale Browser.
2
How do I fix CVE-2018-12448?
To fix CVE-2018-12448, update the Whale Browser to version 1.3.48.4 or later.
3
What impacts does CVE-2018-12448 have on users?
CVE-2018-12448 can potentially mislead users by displaying a fake domain name in the address bar when visiting non-http pages.
4
Which versions of Whale Browser are affected by CVE-2018-12448?
Whale Browser versions before 1.3.48.4 are affected by CVE-2018-12448.
5
Can CVE-2018-12448 lead to phishing attacks?
Yes, CVE-2018-12448 can facilitate phishing attacks by allowing attackers to present a malicious page under a fake domain.