CVE-2016-9473: XSS
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9473?
CVE-2016-9473 is classified as a medium severity vulnerability due to its capability for address bar spoofing.
How do I fix CVE-2016-9473?
To fix CVE-2016-9473, users should update to the latest versions of Brave Browser for iOS and Android.
What systems are affected by CVE-2016-9473?
CVE-2016-9473 affects Brave Browser on iOS versions prior to 1.2.18 and Brave Browser on Android versions before 1.9.56.
What kind of attack does CVE-2016-9473 allow?
CVE-2016-9473 allows attackers to spoof the address bar, potentially tricking users into believing they are on legitimate websites.
Is there any workaround for CVE-2016-9473?
There are no specific workarounds for CVE-2016-9473, so the recommended action is to update the browser.