vendor:
Brave Browser
by:
Sahil Tikoo
6.5
CVSS
MEDIUM
Denial of Service (resource consumption)
20
CWE
Product Name: Brave Browser
Affected Version From: 0.12.5
Affected Version To: 0.13.0
Patch Exists: YES
Related CWE: CVE-2017-18256
CPE: a:brave:brave_browser
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux, Ubuntu, Windows OS
2017
Brave Browser < 0.13.0 Denial of Service (resource consumption) via a long alert() argument.
A denial of service vulnerability exists in Brave Browser versions prior to 0.13.0 due to a long alert() argument. An attacker can exploit this vulnerability by creating a malicious HTML page with a long alert() argument, which when opened in Brave Browser will cause the browser to consume large amounts of resources and eventually crash.
Mitigation:
Upgrade to Brave Browser version 0.13.0 or later.