CVE-2025-69234Critical· 9.1▾ MidnightWhale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
whale < 4.35.351.12Upgrade past the affected range:
whale 4.35.351.12Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62583Critical· 9.8Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
CVE-2025-69235High· 7.5Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
CVE-2026-1486High· 8.8A flaw was found in Keycloak
CVE-2025-59147High· 7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
CVE-2026-103001Medium· 6.5PyJWT is a Python implementation of JSON Web Token standards
CVE-2025-31983Low· 3.7HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header