Information Disclosure Vulnerability in Brave Browser by Brave Software
CVE-2021-22929

6.1MEDIUM

Key Information:

Vendor

Brave

Vendor
CVE Published:
31 August 2021

What is CVE-2021-22929?

An information disclosure vulnerability affects the Brave Browser Desktop, allowing logged warning messages to reveal sensitive timestamps of connections to V2 onion domains in the tor.log file. This could potentially expose users' browsing activities on the Tor network, highlighting a significant privacy concern for those utilizing this browser for secure communications. Users are advised to update to the latest version to mitigate this issue.

Affected Version(s)

https://github.com/brave/brave-core 1.28.62

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.