Brave Shields Domain Reordering Leads to Origin Confusion

Disclosed: 2026-04-13 19:59:26 By mousepadkalilinux12 To brave
Low
Vulnerability Details
## Summary: brave shields shows the domain like 1.attacker.com as attacker.com.1 **steps to reproduced** 1. go to brave browser ( currently i am using ubuntu as os and browser version is Brave 1.89.132 (Official Build) (64-bit) Chromium: 147.0.7727.56 2. go to 1.1.1.1.attacker.com 3. click on brave shield and you can see that the site name changed to attacker.com.1.1.1.1 Here is the POC for 1.attacker.com {F5713016} for 1.1.1.1.attcker.com it changed to attacker.com.1.1.1.1 tricking user that this is from cloudflare DNS. {F5713048} hide the actual domain same as in this report( https://hackerone.com/reports/2501378). but the difference is that in this report we use a very long subdomain but in my case we are using numericals values. {F5713062} but brave in android handles this properly. ## Impact Misrepresentation of domain structure in Brave Shields can mislead users into trusting attacker-controlled sites, enabling phishing attacks.
Actions
View on HackerOne
Report Stats
  • Report ID: 3665151
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report