CVE-2021-22916: Infoleak
In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22916?
CVE-2021-22916 is a vulnerability in Brave Desktop between versions 1.17 and 1.26.60 that occurs when adblocking is enabled and a proxy browser extension is installed, potentially allowing for information disclosure.
How does CVE-2021-22916 affect Brave Desktop?
CVE-2021-22916 affects Brave Desktop versions 1.17 to 1.26.60 when adblocking is enabled and a proxy browser extension is installed.
What is the severity of CVE-2021-22916?
CVE-2021-22916 has a severity rating of medium, with a CVSS score of 5.9.
How can I fix CVE-2021-22916?
To fix CVE-2021-22916, update Brave Desktop to version 1.27.108 or later.
Where can I find more information about CVE-2021-22916?
You can find more information about CVE-2021-22916 on the HackerOne report: [link](https://hackerone.com/reports/1203842).