
We found results for “”
WS-2023-0188
Date: June 22, 2023
Brave for iOS protects privileged JS to native bridges by using random JavaScript handler names and security tokens. However, by altering window.braveBlockRequests property from scripts on the web page, these secret values can be stolen. The impact depends on which bridge is abused. As further features are implemented in the Brave, its potential risk tends to be increased.
Language: Swift
Severity Score
Severity Score
Weakness Type (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
CWE-200CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |