Loading HuntDB...

Brave Shield for iOS is weak against IDN homograph attacks

Low
B
Brave Software
Submitted None
Reported by nishimunea

Vulnerability Details

Technical details and impact analysis

Phishing
## Summary: In most parts of Brave for iOS, including the address bar, protection against IDN attacks are implemented. However, Brave Shield has no countermeasures. For example, when you visit https://www.xn--80ak6aa92e.com , Brave Shield panel in the address bar shows the domain of this site is "apple.com". This may lead users to be deceived into believing that the site is legitimate. ## Products affected: * Brave for iOS (Version 1.45.2) ## Steps To Reproduce: * Visit https://www.xn--80ak6aa92e.com * Open Brave Shield panel from the address bar * "apple.com" is shown in the panel ## Supporting Material/References: * See the screenshot I attached. ## Impact This may lead users to be deceived into believing that the site is legitimate.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$150.00

Submitted

Weakness

Phishing