Vulnerabilities > CVE-2019-25056 - Information Exposure Through Discrepancy vulnerability in Bromite

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
bromite
CWE-203

Summary

In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mechanism.

Vulnerable Configurations

Part Description Count
Application
Bromite
1

Common Weakness Enumeration (CWE)