CVE-2025-62584High· 7.5▾ TwilightWhale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.
whale < 4.33.325.17Upgrade past the affected range:
whale 4.33.325.17Connected by shared product, vendor, weakness, or advisory.
CVE-2025-69235High· 7.5Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
CVE-2025-62585High· 7.5Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.
CVE-2025-69234Critical· 9.1Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
CVE-2025-62583Critical· 9.8Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
CVE-2026-61435High· 8.2PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
CVE-2026-107295High· 7.6Pydantic AI is a Python agent framework for building applications and workflows with Generative AI