Brave Shield for iOS is weak against IDN homograph attacks
Low
B
Brave Software
Submitted None
Actions:
Reported by
nishimunea
Vulnerability Details
Technical details and impact analysis
## Summary:
In most parts of Brave for iOS, including the address bar, protection against IDN attacks are implemented.
However, Brave Shield has no countermeasures.
For example, when you visit https://www.xn--80ak6aa92e.com , Brave Shield panel in the address bar shows the domain of this site is "apple.com".
This may lead users to be deceived into believing that the site is legitimate.
## Products affected:
* Brave for iOS (Version 1.45.2)
## Steps To Reproduce:
* Visit https://www.xn--80ak6aa92e.com
* Open Brave Shield panel from the address bar
* "apple.com" is shown in the panel
## Supporting Material/References:
* See the screenshot I attached.
## Impact
This may lead users to be deceived into believing that the site is legitimate.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$150.00
Submitted
Weakness
Phishing