Inline JavaScript vulnerability in Brave Browser by Brave Software Inc.
CVE-2018-1000815
4.3MEDIUM
What is CVE-2018-1000815?
A security vulnerability exists in the Brave Browser versions 0.22.810 to 0.24.0 that allows websites to execute inline JavaScript, even when script execution is blocked. This issue arises from a flaw in the ContentSettingsObserver::AllowScript() function, enabling potential attackers to track users more easily if exploited. Victims must visit specially crafted websites to trigger this vulnerability. The issue has been addressed in version 0.25.2.
