PT-2025-44560 · Brave · Brave Browser Desktop

Published

2025-10-30

·

Updated

2025-10-31

·

CVE-2025-48980

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Brave Browser versions prior to 1.83.10
Description The "Open Link in Split View" context menu item in Brave Browser Desktop did not correctly handle the SameSite cookie attribute when the split view feature was enabled. Specifically, SameSite=Strict cookies were sent during cross-site navigation using this method.
Recommendations Update Brave Browser to version 1.83.10 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-48980

Affected Products

Brave Browser Desktop