CVE-2025-23086: Medium severity brave browser vulnerability
On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23086?
CVE-2025-23086 has a medium severity rating due to its potential to mislead users regarding file origins.
How do I fix CVE-2025-23086?
To fix CVE-2025-23086, update your Brave Browser to version 1.74.0 or later.
What versions of Brave Browser are affected by CVE-2025-23086?
Brave Browser versions 1.70.x through 1.73.x are affected by CVE-2025-23086.
What kind of issue does CVE-2025-23086 describe?
CVE-2025-23086 describes an incorrect inference of a site's origin in the file selector dialog.
Can CVE-2025-23086 lead to phishing attacks?
Yes, CVE-2025-23086 can potentially lead to phishing attacks by misleading users about file origins.