Description
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing.
Scores
CVSS v3
5.3
EPSS
0.0020
EPSS Percentile
42.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-451
Status
published
Products (1)
navercorp/whale
< 1.14.0
Published
Nov 02, 2021
Tracked Since
Feb 18, 2026