CVE-2021-22917
Homebrew vulnerability analysis and mitigation

Overview

Brave Browser Desktop between versions 1.17 and 1.20 was identified with a critical information disclosure vulnerability (CVE-2021-22917). The vulnerability allowed DNS requests in Tor windows to bypass the Tor network when adblocking was enabled, potentially exposing user browsing information (NVD CVE, Debian Tracker).

Technical details

The vulnerability was assigned a CVSS v3.1 base score of 6.5 (Medium) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. It was categorized under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The issue specifically occurred when adblocking was enabled in Tor windows, causing DNS requests to flow through the system's default DNS settings instead of being routed through the Tor network (NVD CVE).

Impact

The vulnerability could lead to information disclosure by exposing users' DNS requests to their default DNS provider instead of routing them through the Tor network. This could potentially compromise the anonymity of users who specifically chose to use Tor windows for enhanced privacy (NVD CVE).

Exploitability

The vulnerability required user interaction and could be exploited remotely. The attack complexity was rated as low, requiring no special privileges for exploitation. The vulnerability was specifically tied to the browser's adblocking functionality when used in conjunction with Tor windows (NVD CVE).

Mitigation and workarounds

The vulnerability was addressed in versions after 1.20. Users running affected versions (1.17-1.20) were advised to upgrade to a patched version of the Brave Browser (NVD CVE).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72898CRITICAL10
  • NixOS logoNixOS
  • metabase
YesYesAug 10, 2026
CVE-2026-68968HIGH7.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util-odbc
NoYesAug 06, 2026
CVE-2026-68971MEDIUM6.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026
CVE-2026-68969MEDIUM6.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management