CVE-2022-47932 is a denial-of-service vulnerability affecting Brave Browser versions prior to 1.43.34. It allows a remote attacker to crash the browser by tricking a user into opening a specially crafted HTML file containing an ipfs:// or ipns:// URL. This medium-severity vulnerability (CVSS 6.5) requires user interaction and has a high impact on availability, stemming from an incomplete fix for a previous CVE. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.42.51CPE matchmatch criteria | cpe:2.3:a:brave:brave:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.