SameSite Cookie Vulnerability in Brave Browser Desktop
CVE-2025-48980

6.5MEDIUM

Key Information:

Vendor

Brave

Vendor
CVE Published:
30 October 2025

What is CVE-2025-48980?

In versions prior to 1.83.10 of Brave Browser Desktop with the split view feature enabled, a vulnerability allows the 'Open Link in Split View' context menu item to disregard the SameSite cookie attribute. This oversight permits SameSite=Strict cookies to be transmitted during cross-site navigations, leading to potential security conflicts and exposing user sessions to risks.

Affected Version(s)

Desktop Browser 1.83.10

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.