← Back

Browser

browser

Vendor: Brave • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Brave
1Browser
Jun 17, 2026
Dec 30, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc.
1Brave
1Browser
Jun 17, 2026
Jul 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually na...Show more
An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL.Show less
1Brave
1Browser
Jun 17, 2026
Jul 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing through Tor if adblocking was enabled.
1Brave
1Browser
Nov 21, 2024
Jan 3, 2018
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fi...Show more
Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block).Show less
1Brave
1Browser
May 13, 2026
Mar 28, 2017
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.