Brave Shields Domain Reordering Leads to Origin Confusion
Low
Vulnerability Details
## Summary:
brave shields shows the domain like 1.attacker.com as attacker.com.1
**steps to reproduced**
1. go to brave browser ( currently i am using ubuntu as os and browser version is
Brave 1.89.132 (Official Build) (64-bit)
Chromium: 147.0.7727.56
2. go to 1.1.1.1.attacker.com
3. click on brave shield and you can see that the site name changed to attacker.com.1.1.1.1
Here is the POC
for 1.attacker.com
{F5713016}
for 1.1.1.1.attcker.com
it changed to attacker.com.1.1.1.1 tricking user that this is from cloudflare DNS.
{F5713048}
hide the actual domain same as in this report( https://hackerone.com/reports/2501378). but the difference is that in this report we use a very long subdomain but in my case we are using numericals values.
{F5713062}
but brave in android handles this properly.
## Impact
Misrepresentation of domain structure in Brave Shields can mislead users into trusting attacker-controlled sites, enabling phishing attacks.
Actions
View on HackerOneReport Stats
- Report ID: 3665151
- State: Closed
- Substate: resolved
- Upvotes: 4