Navercorp's vulnerability profile, while spanning a limited product portfolio, includes globally distributed applications such as Whale browser and MyBox cloud storage that reach beyond its domestic user base. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure recurs across these products through weakness classes including improper security checks, incorrect privilege assignment, origin validation errors, and input-validation flaws that are characteristic of authentication and boundary-control boundaries in web and application platforms. The modest volume and narrow product scope should not be mistaken for limited risk—these applications' reach and access to user data elevate the significance of each disclosed vulnerability. Defenders should prioritize advisories from this vendor for any deployed instances of its browser or storage products; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Navercorp over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8148HIGH NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks. | May 8, 2026 | 7.8 | 30 | NO | NO |
CVE-2025-62583CRITICAL Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment. | Oct 16, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-24074CRITICAL Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whal | Mar 17, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-69234CRITICAL Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment. | Dec 30, 2025 | 9.1 | 27 | NO | NO |
CVE-2025-53599CRITICAL Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme. | Jul 4, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-62585HIGH Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment. | Oct 16, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-58323HIGH NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege check | Aug 29, 2025 | 7.7 | 25 | NO | NO |
CVE-2025-58322HIGH NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs due to improper privilege checks. | Aug 28, 2025 | 7.8 | 25 | NO | NO |
CVE-2018-12449HIGH The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking. | Oct 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2025-69235HIGH Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment. | Dec 30, 2025 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Navercorp.
Media articles that mention a CVE ID that affects a product developed by Navercorp — matched by CVE ID, not by vendor name.