Homograph attack

Disclosed: 2016-10-14 18:15:01 By jaypatel To brave
Low
Vulnerability Details
## Summary: when we add a site to our **Homepage**, it's not validate a url properly, make sure it's display the **punycode.** ## Products affected: * Brave 0.12.4 (Tested on mac os) ## Steps To Reproduce: * In browser add homepage with IDN http://ebаy.com/ * now close and open browser again * you can see it's redirect to http://xn--eby-7cd.com/ ## References: * https://hackerone.com/reports/29491
Actions
View on HackerOne
Report Stats
  • Report ID: 175286
  • State: Closed
  • Substate: resolved
  • Upvotes: 14
Share this report