Open Redirect Vulnerability in Brave Browser for Android
CVE-2023-28364

6.1MEDIUM

Key Information:

Vendor
CVE Published:
1 July 2023

What is CVE-2023-28364?

An Open Redirect vulnerability was identified in the Brave Browser for Android, impacting versions prior to 1.52.117. This flaw allowed the built-in QR scanner to navigate to scanned URLs without displaying the actual URL to the user. As a result, users could be misled into visiting potentially harmful websites without appropriate warnings. The latest version has been updated to require users to manually navigate to scanned URLs, enhancing security and preventing unauthorized redirects.

Affected Version(s)

Brave Browser Android 1.52.117

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.