PT-2025-44560 · Brave · Brave Browser Desktop

CVE-2025-48980

·

Published

2025-10-30

·

Updated

2025-10-31

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Brave Browser versions prior to 1.83.10
Description The "Open Link in Split View" context menu item in Brave Browser Desktop did not correctly handle the SameSite cookie attribute when the split view feature was enabled. Specifically, SameSite=Strict cookies were sent during cross-site navigation using this method.
Recommendations Update Brave Browser to version 1.83.10 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48980

Affected Products

Brave Browser Desktop