Brave Needs to Stop Contacting Every Website in My Password Manager

Description of the issue:

Brave does not need to show favicons in Password Manager. It doesn’t need to contact every website in my Password Manager, especially when I’m only looking for one password. The only way to stop Brave from needlessly contacting every website is to quit Brave immediately after I obtain the needed username/password. This activity needs to stop!

How can this issue be reproduced?

  1. Open Password Manager.
  2. Watch Brave contact every website listed in your password manager.
  3. Shake head in disbelief this hasn’t been stopped years ago.

Expected result:

Brave stops contacting every website in password manager.

Brave Version( check About Brave):

Version 1.73.101 Chromium: 131.0.6778.139 (Official Build) (arm64)

@fmarier actually hoping you might have some thought on this. Especially thinking about how some are seeing things flagged by like Malwarebytes when they open their Password Manager.

I’m not sure how people are tracking, but I’m guessing there is some sort of call from the browser to all the websites? And if so, could that be any potential safety/security risk by making whatever “call” it’s making to these domains?

Malwarebytes examples are like the three things linked below.

@Jagermeister by what method are you using to watch calls from the browser to the website(s)?

It looks like it uses the favicon cache rather than making any calls to websites: I just opened Password Manager and 2 of the entries had default grey favicons. I went to the homepage of one of those entries, then reloaded Password Manager and the favicon for that site was displayed.

It may be. But I guess also am questioning the idea of how Malwarebytes and all would be triggering the messages it is based on entries in a person’s password manager. There should be something going on. I mean, I doubt Malwarebytes has full access to all our saved passwords and is checking it, otherwise would think its warning would be more specific.

General info #1: 1Password includes a setting, that, when enabled, allows 1Password to update the favicons of login-websites. (I leave that switch, disabled.)

General info #2: On iOS devices, Brave Browser randomly changes / flips (back and forth) website favicons to be actual or generic. Occurs for the home screen, and occurs among the bookmarks. (No idea why.)

I use Little Snitch.

I say that Brave is calling for favicons because why else would Brave call every website in the manager? Nothing else would seem correct.

That is correct, it appears to be in order to fetch the favicon data from each site. I’ve opened an issue for this here: