Denial of Service Vulnerability in Brave Browser by Brave Software
CVE-2022-47933

6.5MEDIUM

Key Information:

Vendor

Brave

Status
Vendor
CVE Published:
24 December 2022

What is CVE-2022-47933?

A vulnerability in the Brave Browser prior to version 1.42.51 allows remote attackers to induce a denial of service. This security flaw is triggered by a specially crafted HTML file that interacts with the IPFS scheme, resulting in an uncaught exception in the ipfs::OnBeforeURLRequest_IPFSRedirectWork() function. This issue can disrupt browser functionality, leaving users exposed to further risks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.