CVE-2022-24074: Critical severity naver whale browser vulnerability
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-24074.
What is the title of this vulnerability?
The title of this vulnerability is 'Whale Bridge a default extension in Whale browser before 3.12.129.18 allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.'
What is the affected software?
The affected software is Navercorp Whale browser versions up to 3.12.129.18.
What is the severity of this vulnerability?
The severity of this vulnerability is critical with a CVSS score of 9.8.
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update the Navercorp Whale browser to version 3.12.129.18 or higher.