VYPR
Medium severity5.9NVD Advisory· Published Jul 12, 2021· Updated Jun 17, 2026

CVE-2021-22916

CVE-2021-22916

Description

In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible information disclosure.

Affected products

3
  • cpe:2.3:a:brave:brave:*:*:*:*:*:*:*:*
    Range: >=1.17.0,<=1.26.60
  • Brave/Brave Desktopdescription
  • Range: 1.17 - 1.26.60

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.