CVE-2021-33593
Estado: ModificadaMedia (5.3)—
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.71%
- Percentil entre todas las CVEs puntuadas: 52
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-451
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-33593",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@navercorp.com",
"affectedData": [
{
"vendor": "NAVER",
"product": "NAVER Whale browser",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "1.14.0",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-11-02T07:15:07.220",
"references": [
{
"url": "https://cve.naver.com/detail/cve-2021-43059",
"tags": [
"Broken Link",
"Not Applicable"
],
"source": "cve@navercorp.com"
},
{
"url": "https://cve.naver.com/detail/cve-2021-43059",
"tags": [
"Broken Link",
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@navercorp.com",
"description": [
{
"lang": "en",
"value": "CWE-451"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing."
},
{
"lang": "es",
"value": "Whale browser para iOS versiones anteriores a 1.14.0 presenta un problema de inconsistencia en la interfaz de usuario que permite a un atacante ofuscar la barra de direcciones, que puede conllevar a una suplantación de la barra de direcciones"
}
],
"lastModified": "2026-06-17T03:54:50.570",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:navercorp:whale:*:*:*:*:*:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "549F9B1E-B0BF-40BB-B8C6-D693393A2F52",
"versionEndExcluding": "1.14.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@navercorp.com"
}