CVE-2021-22916

In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible information disclosure.
References
Link Resource
https://hackerone.com/reports/1203842 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:brave:brave:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-07-12 11:15

Updated : 2024-02-28 18:28


NVD link : CVE-2021-22916

Mitre link : CVE-2021-22916

CVE.ORG link : CVE-2021-22916


JSON object : View

Products Affected

brave

  • brave
CWE
NVD-CWE-Other CWE-200

Exposure of Sensitive Information to an Unauthorized Actor