Inline JavaScript vulnerability in Brave Browser by Brave Software Inc.
CVE-2018-1000815

4.3MEDIUM

Key Information:

Vendor

Brave

Status
Vendor
CVE Published:
20 December 2018

What is CVE-2018-1000815?

A security vulnerability exists in the Brave Browser versions 0.22.810 to 0.24.0 that allows websites to execute inline JavaScript, even when script execution is blocked. This issue arises from a flaw in the ContentSettingsObserver::AllowScript() function, enabling potential attackers to track users more easily if exploited. Victims must visit specially crafted websites to trigger this vulnerability. The issue has been addressed in version 0.25.2.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.