VYPR

Brave desktop

by Brave

CVEs (4)

  • CVE-2025-48980MedOct 31, 2025
    risk 0.42cvss 6.5epss 0.00

    In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this…

  • CVE-2021-22916MedJul 12, 2021
    risk 0.38cvss 5.9epss 0.02

    In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible…

  • CVE-2020-8276MedNov 9, 2020
    risk 0.36cvss 5.5epss 0.00

    The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows. The intended behavior was to log the timestamp for incognito windows excluding…

  • CVE-2023-28360MedMay 11, 2023
    risk 0.28cvss 4.3epss 0.01

    An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file there was no download safety check dialog presented to the user.