CVE-2023-28364: Brave Browser

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL.

Affected products

  • Brave Browser: before 1.52.117 (fixed in 1.52.117)

Published 2023-07-01. Last modified 2026-06-17.