PT-2017-10164 · Brave · Brave Browser
Aaditya_Purani
·
Published
2017-03-28
·
Updated
2021-03-19
·
CVE-2016-9473
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Brave Browser iOS versions prior to 1.2.18
Brave Browser Android versions prior to 1.9.56
Description
The issue allows attackers to trick victims by displaying a malicious page for legitimate domain names through Full Address Bar Spoofing.
Recommendations
For Brave Browser iOS versions prior to 1.2.18, update to version 1.2.18 or later.
For Brave Browser Android versions prior to 1.9.56, update to version 1.9.56 or later.
Exploit
Fix
XSS
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brave Browser