An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://hackerone.com/reports/1249056 | exploit third party advisory patch |