PT-2025-4816 · Brave · Brave Browser

Syarif07

·

Published

2025-01-21

·

Updated

2025-07-20

·

CVE-2025-23086

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Brave Browser versions 1.70.x through 1.73.x
Description The issue arises from a feature that displays a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However, the origin is not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.
Recommendations For Brave Browser versions 1.70.x through 1.73.x, consider disabling the feature that shows a site's origin on the OS-provided file selector dialog until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-23086

Affected Products

Brave Browser