First published: Wed May 03 2017(Updated: )
Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://safe.example.com@unsafe.example.com/ is displayed without a clear UI indication that it is not a resource on the safe.example.com web site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Brave Browser | =0.12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-8458 is considered moderate due to the potential for phishing attacks.
To fix CVE-2017-8458, users should upgrade to a version of Brave newer than 0.12.4 that addresses the URI obfuscation issue.
CVE-2017-8458 is classified as a URI obfuscation vulnerability.
Brave version 0.12.4 is the affected version for CVE-2017-8458.
If CVE-2017-8458 is not addressed, users may be susceptible to phishing scams due to misleading URL displays.