What the vulnerability does
01Description
Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brave: from n/a through <= 0.8.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brave: from n/a through <= 0.8.3.
Explanation of Vulnerability in Simple Terms
Brave versions 0.8.3 and earlier lack proper authorization checks, allowing unauthenticated network attackers to read sensitive information. No user interaction is required. The vulnerability has a CVSS score of 5.3 (medium severity) and affects confidentiality but not integrity or availability.
What an attacker can do
Read sensitive information without authentication over the network.
Potential impact on your site
Not applicable—Brave is a browser, not a CMS plugin or module.
Conditions required to exploit
Network access to the affected Brave instance; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities