File Origin Spoofing Vulnerability in Brave Browser
CVE-2025-23086

6.1MEDIUM

Key Information:

Vendor

Brave

Vendor
CVE Published:
21 January 2025

What is CVE-2025-23086?

The Brave Browser versions 1.70.x to 1.73.x feature a file selector dialog that showcases a site's origin during file uploads or downloads. However, an oversight in origin inference can occur under certain conditions. If a malicious site uses an open redirect vulnerability on a trusted site, it may trigger downloads that misleadingly appear to originate from the trusted entity in the file selector. This could mislead users into executing potentially harmful downloads while believing they are interacting with a secure, trusted source.

Affected Version(s)

Desktop Browser 1.74.48

Desktop Browser 1.70.117

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.