Open Redirect Vulnerability in Brave Browser
CVE-2023-22798

6.1MEDIUM

Key Information:

Vendor

Brave

Vendor
CVE Published:
9 February 2023

What is CVE-2023-22798?

An open redirect vulnerability exists in earlier versions of Brave Browser due to the removal of redirect interceptors on major platforms such as Facebook. This removal, part of a feature called 'debouncing', aims to eliminate unnecessary redirects used for user tracking. However, it inadvertently exposes users to potential open redirect risks, potentially allowing malicious actors to redirect users to untrusted destinations. It is essential for users to be aware of this vulnerability to safeguard their online activities.

Affected Version(s)

https://github.com/brave/adblock-lists 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.