Brave Doesn't Require Password to View/edit Saved Payment Methods

Brave Doesn’t Require Password to view/edit Saved Payment Methods. Seems like a security issue. Chrome requires you to enter your password to view/edit payment methods.

Screen Recording: https://www.youtube.com/watch?v=GMPqpqdXl4I

OS: macOS Ventura 13.6.9
Brave: 1.68.137 Chromium: 127.0.6533.100 (Official Build) (x86_64)

How to reproduce:
click the hamburger menu (3 horizontal lines in the top right)
hover over “Passwords and Autofill”
click “Payment Methods”
for one of the saved payment methods, click the 3 vertical dots on the right
choose “edit”
notice you can now view/edit the payment details including the entire CC number and expiration date

@11plustwo,
While I agree that it should ask for a password in general, this behavior was inherited from Chrome.

It does not — it is the same behavior in Chrome as it is Brave:

I promise you chrome does require you to log in to view/change payment methods. Please go look at chrome. When you go to payment methods, you can view them with their nicknames, but to view full card info, you have to log in.

It may be different in windows. I’m on mac. I just verified that chrome asks you to authenticate to view/edit

@11plustwo I believe there’s a bit of a misunderstanding. I just went to Chrome to test and it showed a card I had saved before. But there was no edit button or anything. Instead, it had:

image

Clicking that took me to a window where it wanted to use passkey to login. I think the reason for this though is the icon you see, which is that the card is saved on Google Pay, which is tied into my Google Account. It’s not expressly stored in the browser but is fetching and syncing from the account.

In comparison, if we had added manually or set it for the browser instead, you see this on creation:

image

Notice the bottom part that says it will be saved to the device only?

This new one will show like below:

image

And if I click the hamburger menu (the three dots), it will let me Edit and open the prompt like below:

image

Essentially both you and @Mattches are correct, but on different aspects.

1 Like

Yep, this is correct. Thanks for the clarification @Saoiray.

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.