Brave
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Brave product.
RSS Feeds for Brave security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Brave products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Brave Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Brave. Last year, in 2025 Brave had 3 security vulnerabilities published. Right now, Brave is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 3 | 9.45 |
| 2024 | 1 | 0.00 |
| 2023 | 4 | 5.65 |
| 2022 | 4 | 6.20 |
| 2021 | 4 | 5.95 |
| 2020 | 1 | 0.00 |
| 2019 | 0 | 0.00 |
| 2018 | 3 | 4.30 |
It may take a day or so for new Brave vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Brave Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2025-68508 | Dec 24, 2025 |
Brave Browser <0.8.3 Missing Auth in brave-popup-builderMissing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brave: from n/a through <= 0.8.3. |
|
| CVE-2025-48980 | Oct 30, 2025 |
SameSite Cookie Bypass in Brave <1.83.10 Split ViewIn Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method. |
|
| CVE-2025-7710 | Aug 02, 2025 |
Auth Bypass in WP Brave Conversion Engine PRO <=0.7.7The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for unauthenticated attackers to log in as other users, including administrators. |
|
| CVE-2024-35655 | Jun 04, 2024 |
Brave Popup Builder <0.6.9 Stored XSS via Improper Input NeutralizationImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brave Brave brave-popup-builder allows DOM-Based XSS.This issue affects Brave: from n/a through <= 0.6.9. |
|
| CVE-2023-52263 | Dec 30, 2023 |
Brave Browser <=1.59.39: WebUI Factory Schema FlawBrave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc. |
|
| CVE-2023-28364 | Jul 01, 2023 |
Brave Android QR Scanner Open Redirect ( 1.52.117)An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL. |
|
| CVE-2023-28360 | May 11, 2023 |
Brave Browser <1.48.171 - Omitted Download Safety DialogAn omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file there was no download safety check dialog presented to the user. |
|
| CVE-2023-22798 | Feb 09, 2023 |
Brave Redirect Debounce Removal Enables Open RedirectsPrior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websites like Facebook in which the redirect interceptor may have been there for security purposes. This could potentially cause open redirects on these websites. Brave's redirect interceptor removal feature is known as "debouncing" and is intended to remove unnecessary redirects that track users across the web. |
|
| CVE-2022-47933 | Dec 24, 2022 |
Brave Browser IPFS DoS before 1.42.51Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme. This vulnerability is caused by an uncaught exception in the function ipfs::OnBeforeURLRequest_IPFSRedirectWork() in ipfs_redirect_network_delegate_helper.cc. |
|
| CVE-2022-47932 | Dec 24, 2022 |
Brave Browser 1.43.34 DoS via ipfs:// in HTMLBrave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This vulnerability is caused by an incomplete fix for CVE-2022-47933. |
|