Briar is a secure messaging application designed for resilient, decentralized communication, and its vulnerability profile centers on the single Briar product with recurring concerns around cryptographic and authorization implementation. The durable signal from observed disclosures reflects the sensitivity of a privacy-focused messaging platform: weaknesses cluster around integrity validation, encryption strength, missing authorization checks, and resource-consumption boundaries—all critical to maintaining confidentiality and availability in an adversarial environment. Current exploitation activity, severity distribution, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Briarproject over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33980HIGH Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contac | May 24, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-33983HIGH The Introduction Client in Briar through 1.5.3 does not implement out-of-band verification for the public keys of introducees. An introducer can launch man-in-the-middle attacks ag | May 24, 2023 | 7.4 | 23 | NO | NO |
CVE-2023-33981MEDIUM Briar before 1.4.22 allows attackers to spoof other users' messages in a blog, forum, or private group, but each spoofed message would need to be an exact duplicate of a legitimate | May 24, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-33982MEDIUM Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts. | May 24, 2023 | 5.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Briarproject.
Media articles that mention a CVE ID that affects a product developed by Briarproject — matched by CVE ID, not by vendor name.