PT-2021-15273 · Brave · Brave Desktop

Neeythann

·

Published

2021-07-12

·

Updated

2022-08-30

·

CVE-2021-22916

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Brave Desktop versions 1.17 through 1.26.60
Description The issue occurs when adblocking is enabled and a proxy browser extension is installed in Brave Desktop. The CNAME adblocking feature makes DNS requests using the system DNS settings instead of the extension's proxy settings, potentially leading to information disclosure.
Recommendations For versions 1.17 through 1.26.60, consider disabling the CNAME adblocking feature or the proxy browser extension as a temporary workaround to minimize the risk of information disclosure.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2021-22916

Affected Products

Brave Desktop