CVE-2016-9473: Brave Browser

Medium severity, CVSS 4.7. EPSS: 1.9% chance of exploitation in the next 30 days.

Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.

Affected products

  • Brave Browser: before 1.2.18 (fixed in 1.2.18); before 1.9.56 (fixed in 1.9.56)

Published 2017-03-28. Last modified 2026-06-17.