CVE Vulnerabilities

CVE-2025-48980

Reliance on Cookies without Validation and Integrity Checking

Published: Oct 31, 2025 | Modified: Dec 01, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the Open Link in Split View context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method.

Weakness

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

Potential Mitigations

References