In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/3253725 |
|
History
Fri, 31 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brave
Brave brave Brave brave Browser Brave browser |
|
| Vendors & Products |
Brave
Brave brave Brave brave Browser Brave browser |
Thu, 30 Oct 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published: 2025-10-30T23:29:44.075Z
Updated: 2025-10-31T14:48:00.254Z
Reserved: 2025-05-29T15:00:04.773Z
Link: CVE-2025-48980
Updated: 2025-10-31T14:47:52.344Z
Status : Received
Published: 2025-10-31T00:15:36.327
Modified: 2025-10-31T00:15:36.327
Link: CVE-2025-48980
No data.