SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22916

In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings,…

MEDIUM 5.9EPSS 2.99%

Does this matter?

Lower severity and a low EPSS score (2.99%). Track it; it rarely justifies an emergency change on its own.

Description

In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible information disclosure.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
2.99% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
brave/brave
Source
support@hackerone.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.