CVE-2025-48980 Details
Description
In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method.
A vulnerability exists in Brave Browser Desktop versions prior to 1.83.10 with the split view feature enabled. The 'Open Link in Split View' context menu option fails to adhere to the SameSite cookie policy, allowing SameSite=Strict cookies to be sent during cross-site navigation. This behavior bypasses the intended cookie restrictions, potentially leading to Cross-Site Request Forgery (CSRF) vulnerabilities.
Users can update to Brave Browser Desktop version 1.83.10 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 31, 2025CISA-ADP
Assessed Oct 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hackerone.com/reports/3253725 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-565 | Reliance on Cookies without Validation and Integrity Checking | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Brave Browser | 1.80.120 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 1, 2025 | CVE Modified | CISA-ADP |
| Oct 31, 2025 | New CVE Received | [email protected] |
Volerion