Description
In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible information disclosure.
References
https://hackerone.com/reports/1203842
Third Party Advisory
https://hackerone.com/reports/1203842
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
5.9 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-07-12T09:15:07.770Z
4 years agoLast modified
2024-11-21T04:50:54.547Z
1 year ago