First published: Fri Jun 30 2023(Updated: )
An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Brave Browser | <1.52.117 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-28364.
The severity of CVE-2023-28364 is medium.
The affected software for CVE-2023-28364 is Brave Browser version up to exclusive 1.52.117.
The description of CVE-2023-28364 is that an Open Redirect vulnerability exists in Brave Browser Android, where the built-in QR scanner navigated to scanned URLs automatically without showing the URL first, but now the user must manually navigate to the URL.
Yes, the fix for CVE-2023-28364 is to update Brave Browser to version 1.52.117 or later.