CVE-2024-37406: Input Validation
Published Sep 18, 2024
·Updated
In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domain confusion.
Affected Software
1 affected component
Brave Brave Android<1.67.116
Event History
Sep 18, 2024
CVE Published
via MITRE·09:54 PM
Data Sourced
via MITRE·09:54 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37406?
CVE-2024-37406 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-37406?
To mitigate CVE-2024-37406, update Brave Android to version 1.67.116 or later.
3
What impact does CVE-2024-37406 have on user privacy?
CVE-2024-37406 could lead to domain confusion, potentially exposing users to phishing attacks.
4
Is my device at risk if I use an older version of Brave Android?
Yes, using an older version of Brave Android prior to v1.67.116 puts your device at risk due to CVE-2024-37406.
5
What does it mean that domains are elided from the right instead of the left in CVE-2024-37406?
This means that when viewing domains in the Brave Shields popup, important parts of the domain names may be hidden, which could mislead users.