CVE-2020-9754 describes a bypass vulnerability in the NAVER Whale mobile browser, affecting versions prior to 1.10.6.2. An attacker can circumvent the browser's unlock function by utilizing incognito mode, potentially gaining unauthorized access to the browser's content. This medium-severity vulnerability (CVSS 5.3) requires no user interaction or complex attack vectors, but its impact is limited to integrity, meaning it doesn't directly lead to data confidentiality or availability compromise. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.6.2CPE matchmatch criteria | cpe:2.3:a:navercorp:whale:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.