In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/3253725 |
|
History
Mon, 01 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-565 |
Fri, 31 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brave
Brave brave Brave brave Browser Brave browser |
|
| Vendors & Products |
Brave
Brave brave Brave brave Browser Brave browser |
Thu, 30 Oct 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published: 2025-10-30T23:29:44.075Z
Updated: 2025-12-01T20:22:29.067Z
Reserved: 2025-05-29T15:00:04.773Z
Link: CVE-2025-48980
Updated: 2025-10-31T14:47:52.344Z
Status : Awaiting Analysis
Published: 2025-10-31T00:15:36.327
Modified: 2025-12-01T21:15:50.250
Link: CVE-2025-48980
No data.