In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domain confusion.
References
History

Thu, 19 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Brave
Brave android Browser
Weaknesses CWE-20
CPEs cpe:2.3:a:brave:android_browser:*:*:*:*:*:*:*:*
Vendors & Products Brave
Brave android Browser
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 22:15:00 +0000

Type Values Removed Values Added
Description In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domain confusion.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2024-09-18T21:54:09.120Z

Updated: 2024-09-19T13:45:15.401Z

Reserved: 2024-06-08T01:04:07.093Z

Link: CVE-2024-37406

cve-icon Vulnrichment

Updated: 2024-09-19T13:45:08.396Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-18T22:15:04.573

Modified: 2024-09-20T12:30:17.483

Link: CVE-2024-37406

cve-icon Redhat

No data.