CVE-2018-7635: Input Validation
Published Jul 3, 2018
·Updated
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domain name.
Affected Software
1 affected component
Navercorp Whale<1.0.41.8
Event History
Jul 3, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7635?
The severity of CVE-2018-7635 is rated as medium with a CVSS score of 5.3.
2
How does CVE-2018-7635 affect Whale Browser?
CVE-2018-7635 affects Whale Browser versions up to (but not including) 1.0.41.8 by displaying no URL information on the address bar when visiting a blank page.
3
What is the vulnerability description of CVE-2018-7635?
CVE-2018-7635 allows an attacker to display a malicious web page with a fake domain name by showing only the title of a web page on the browser's address bar when visiting a blank page.