This page lists publicly disclosed CVE vulnerabilities affecting brave browser (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-52263 | Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc. | [email protected] | 6.1 | 0.07% | 2023-12-30 | 2024-11-21 |
| CVE-2023-28364 | An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL. | [email protected] | 6.1 | 0.15% | 2023-07-01 | 2024-11-21 |
| CVE-2021-22917 | Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing through Tor if adblocking was enabled. | [email protected] | 6.5 | 0.30% | 2021-07-12 | 2024-11-21 |
| CVE-2017-1000461 | Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block). | [email protected] | 4.7 | 0.22% | 2018-01-03 | 2024-11-21 |
| CVE-2016-9473 | Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names. | [email protected] | 4.7 | 0.66% | 2017-03-28 | 2026-05-13 |