CVE-2025-69235High· 7.5▾ TwilightWhale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
whale < 4.35.351.12Upgrade past the affected range:
whale 4.35.351.12Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62583Critical· 9.8Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
CVE-2025-14331Medium· 6.5Same-origin policy bypass in the Request Handling component
CVE-2025-69260High· 7.5A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit th…
CVE-2025-69258Critical· 9.8A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM…
CVE-2025-69259High· 7.5A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to e…
CVE-2025-66592Medium· 6.1An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.