Brave Software maintains a focused product portfolio centered on its eponymous privacy-oriented web browser, which occupies a notable position in the consumer browser landscape. The vendor's vulnerability disclosures cluster around web-browser attack surface: information disclosure, input validation failures, open redirects, and cleartext storage of sensitive data—weakness classes characteristic of client-side web applications and integration of third-party components. A moderate tendency exists for these vulnerabilities to acquire public exploit code, reflecting the accessibility of browser targets for security research and proof-of-concept development. Defenders tracking Brave deployments should prioritize browser updates as part of their endpoint security posture; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brave over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10718HIGH Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service. | Apr 4, 2018 | 7.5 | 40 | NO | YES |
CVE-2025-68508CRITICAL Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brave: from n/a th | Dec 24, 2025 | 9.1 | 32 | NO | NO |
CVE-2017-18256MEDIUM Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaScript code, because window dialogs are m | Apr 4, 2018 | 6.5 | 31 | NO | YES |
CVE-2021-45884HIGH In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additional DNS requests are issued outsi | Dec 27, 2021 | 7.5 | 26 | NO | NO |
CVE-2022-47933MEDIUM Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme. This vulnerability is caused by an unca | Dec 24, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-47932MEDIUM Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This vulnerability is caused by | Dec 24, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-30334MEDIUM Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers. NOTE: although this was fixed by Brave, the Brave documenta | May 7, 2022 | 5.3 | 23 | NO | NO |
CVE-2017-8459MEDIUM Brave 0.12.4 has a Status Bar Obfuscation issue in which a redirection target is shown in a possibly unexpected way. NOTE: third parties dispute this issue because it is a behavior | May 3, 2017 | 6.5 | 23 | NO | NO |
CVE-2017-8458MEDIUM Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://[email protected]/ is displayed without a clear UI indication that it is not a resource | May 3, 2017 | 6.5 | 23 | NO | NO |
CVE-2021-22929MEDIUM An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor | Aug 31, 2021 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brave.
Media articles that mention a CVE ID that affects a product developed by Brave — matched by CVE ID, not by vendor name.