CVE-2024-40618: Naver Whale Browser

Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension.

Affected products

  • Naver Naver Whale Browser
  • Naver Whale Browser: before 3.26.244.21 (fixed in 3.26.244.21)

Published 2024-07-11. Last modified 2026-06-17.