CVE-2023-52263: Brave Browser

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc.

Affected products

  • Brave Browser: before 1.59.40 (fixed in 1.59.40)

Published 2023-12-30. Last modified 2026-06-17.