PT-2022-16453 · Unknown · Whale Bridge+1

Young Min Kim

·

Published

2022-03-17

·

Updated

2023-06-30

·

CVE-2022-24074

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Whale browser versions prior to 3.12.129.18
Description The issue allows Whale Bridge, a default extension in Whale browser, to receive any SendMessage request from the content script itself. This could lead to controlling Whale Bridge if the rendering process compromises.
Recommendations For versions prior to 3.12.129.18, update to version 3.12.129.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the Whale Bridge extension to minimize the risk of exploitation.

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2022-24074

Affected Products

Whale Bridge
Whale Browser