
Cloud Vulnerability DB
A community-led vulnerabilities database
Brave Browser Desktop between versions 1.17 and 1.20 was identified with a critical information disclosure vulnerability (CVE-2021-22917). The vulnerability allowed DNS requests in Tor windows to bypass the Tor network when adblocking was enabled, potentially exposing user browsing information (NVD CVE, Debian Tracker).
The vulnerability was assigned a CVSS v3.1 base score of 6.5 (Medium) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. It was categorized under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The issue specifically occurred when adblocking was enabled in Tor windows, causing DNS requests to flow through the system's default DNS settings instead of being routed through the Tor network (NVD CVE).
The vulnerability could lead to information disclosure by exposing users' DNS requests to their default DNS provider instead of routing them through the Tor network. This could potentially compromise the anonymity of users who specifically chose to use Tor windows for enhanced privacy (NVD CVE).
The vulnerability required user interaction and could be exploited remotely. The attack complexity was rated as low, requiring no special privileges for exploitation. The vulnerability was specifically tied to the browser's adblocking functionality when used in conjunction with Tor windows (NVD CVE).
The vulnerability was addressed in versions after 1.20. Users running affected versions (1.17-1.20) were advised to upgrade to a patched version of the Brave Browser (NVD CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."